Vulnerability Description
The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simple Schools Staff Directory Project | Simple Schools Staff Directory | <= 1.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/8b5b5b57-50c5-4cd8-9171-168c3e9df46aExploitThird Party Advisory
- https://wpscan.com/vulnerability/8b5b5b57-50c5-4cd8-9171-168c3e9df46aExploitThird Party Advisory
FAQ
What is CVE-2021-24663?
CVE-2021-24663 is a vulnerability with a CVSS score of 7.2 (HIGH). The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitra...
How severe is CVE-2021-24663?
CVE-2021-24663 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24663?
Check the references section above for vendor advisories and patch information. Affected products include: Simple Schools Staff Directory Project Simple Schools Staff Directory.