CVE-2021-24145
high · 7.2A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.
7.2
CVSS
87.2%
EPSS (exploit prob.)
100th
EPSS percentile
2021-03-18
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| webnus | modern_events_calendar_lite | < 5.16.5 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/163346/WordPress-Modern-Events-Calendar-5.16.2-Shell-Upload.html
- http://packetstormsecurity.com/files/163672/WordPress-Modern-Events-Calendar-Remote-Code-Execution.html
- https://wpscan.com/vulnerability/f42cc26b-9aab-4824-8168-b5b8571d1610
- http://packetstormsecurity.com/files/163346/WordPress-Modern-Events-Calendar-5.16.2-Shell-Upload.html
- http://packetstormsecurity.com/files/163672/WordPress-Modern-Events-Calendar-Remote-Code-Execution.html
- https://wpscan.com/vulnerability/f42cc26b-9aab-4824-8168-b5b8571d1610
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-24145