CVE-2021-24890
Scripts Organizer < 3.0 - Unauthenticated Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file
El plugin Scripts Organizer de WordPress versiones anteriores a 3.0 no presenta comprobaciones de capacidad y de tipo CSRF en la acción saveScript AJAX, disponible tanto para usuarios no autenticados como autenticados, y no valida la entrada del usuario de ninguna manera, lo que podría permitir a usuarios no autenticados poner código PHP arbitrario en un archivo
The Scripts Organizer plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, but not including, 3.0. This is due to missing capability checks in one of its AJAX actions that is accessible to unauthenticated users. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2022-09-05 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-434: Unrestricted Upload of File with Dangerous Type
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://dplugins.com/products/scripts-organizer | Product |
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/f3b450d2-84ce-4c13-ad6a-b60785dee7e7 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dplugins Search vendor "Dplugins" | Scripts Organizer Search vendor "Dplugins" for product "Scripts Organizer" | < 3.0 Search vendor "Dplugins" for product "Scripts Organizer" and version " < 3.0" | wordpress |
Affected
|