CVE-2021-24223 Information
Jun 07, 2022
cve
Description
The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed as any file can be uploaded. The uploaded filename might be hard to guess as it’s generated with md5(uniqid(rand())) however in the case of misconfigured servers with Directory listing enabled accessing it is trivial.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/d7a72183-0cd1-45de-b98b-2e295b27e5db https://github.com/jinhuang1102/CVE-ID-Reports/blob/12863f80ced5361e2e2c3f7209566ab3730aa37b/N5_upload.md
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: