← volver
CVE-2021-25082explotación observadaCWE-22

Popup Builder < 4.0.7 - LFI to RCE

40Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actepss 5.2%
de la publicación al arma
Publicada en NVD21 feb
VulnCheck+301d
probabilidad de explotación
5.2%top 8% de las CVE
explotación observada
VulnCheck
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR