← volver
CVE-2021-24642

Scroll Baner <= 1.0 - CSRF to RCE

EPSS 0.6%CWE-352CWE-79
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
18 oct 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS
Productos afectados
Unknown · Scroll Baner

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →