CVE Feed

    Dashboard / CVE / CVE-2021-24563

    CVE-2021-24563

    The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

    Published:Oct 11, 2021
    Last Modified:Nov 21, 2024
    EPS:Oct 11, 2021
    EPSS Score:0.29956
    CVSS Score:6.1

    Affected Products

    Vendor
    Frontend Uploader Project
    Product
    Frontend Uploader

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High