CVE-2021-24490
MEDIUM 6.8EPSS 0.6%
The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS
- CVSS v3.1
- 6.8 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.0 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P - EPSS
- 0.56% chance of exploitation in the next 30 days, 44th percentile
- Published
- 2021-09-13
- Updated
- 2024-08-03