← voltar
CVE-2021-25004CWE-552

SEUR Oficial < 1.7.2 - Admin+ Arbitrary File Download

3Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackepss 1.2%
probabilidade de exploração
1.2%top 36% das CVEs
exploração observada
nãonenhuma fonte reporta
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.
Produtos afetados
Unknown · SEUR Oficial