| ID | CVE-2020-35945 | ||||||
| Sažetak | An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:L/Au:S/C:P/I:P/A:P | ||||||
| Zadnje važnije ažuriranje | 04-02-2026 - 18:54 | ||||||
| Objavljeno | 01-01-2021 - 04:15 |

