CVE Feed

    Dashboard / CVE / CVE-2021-24222

    CVE-2021-24222

    The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

    Published:Apr 12, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 12, 2021
    EPSS Score:0.05245
    CVSS Score:9.8

    Affected Products

    Vendor
    Williamluis
    Product
    Wp-curriculo Vitae Free

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High