The Import any XML or CSV File to...... CVE-2023-7082

- AV AC AU C I A
发布: 2024-01-22
修订: 2024-01-26

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type leading to remote code execution.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息