CVE-2021-4225
SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
El plugin SP Project & Document Manager de WordPress versiones anteriores a 4.24, permite a cualquier usuario autenticado, como los suscriptores, subir archivos. El plugin intenta evitar que sean subidos archivos PHP y otros similares que podrÃan ejecutarse en el servidor, comprobando la extensión del archivo. Se ha detectado que en los servidores de Windows, las comprobaciones de seguridad establecidas eran insuficientes, permitiendo a malos actores cargar potencialmente puertas traseras en sitios vulnerables
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-28 CVE Published
- 2022-03-31 CVE Reserved
- 2023-11-16 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/pang0lin/CVEproject/blob/main/wordpress_SP-Project_fileupload.md | 2024-08-03 | |
https://wpscan.com/vulnerability/bd1083d1-edcc-482e-a8a9-c8b6c8d417bd | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Smartypantsplugins Search vendor "Smartypantsplugins" | Sp Project \& Document Manager Search vendor "Smartypantsplugins" for product "Sp Project \& Document Manager" | < 4.24 Search vendor "Smartypantsplugins" for product "Sp Project \& Document Manager" and version " < 4.24" | wordpress |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|