CVE-2021-24236

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.
References
Configurations

Configuration 1

cpe:2.3:a:imagements_project:imagements:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-05-06 01:15

Updated : 2021-05-11 06:48


NVD link : CVE-2021-24236

Mitre link : CVE-2021-24236

Products Affected
No products.
CWE