PoC Index

CVE-2021-24145

HIGH 7.2EPSS 87.3%

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
87.31% chance of exploitation in the next 30 days, 100th percentile
Nuclei
high · CWE-434
Published
2021-03-18
Updated
2024-08-03

Proof-of-concept exploits (4)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related