Aller au contenu

Fiche vulnérabilité

CVE-2021-24347 : faille élevée smartypantsplugins sp project \&… (CVSS 8.8)

Description

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
14 juin 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • smartypantsplugins sp project \& document manager

Références

Rechercher une autre vulnérabilité dans la base CVE