← back
CVE-2024-50427

WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability

CVSS 9.9 CRITICALEPSS 1.0%CWE-434
Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
devsoftbaltic · SurveyJS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →