CVE-2021-24377
Autoptimize < 2.7.8 - Race Condition leading to RCE
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
21 jun 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.
Productos afectados
Unknown · Autoptimize¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →