| ID | CVE-2021-24280 | ||||||
| Sažetak | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects. | ||||||
| Reference | |||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:L/Au:S/C:P/I:P/A:P | ||||||
| Zadnje važnije ažuriranje | 17-05-2021 - 19:11 | ||||||
| Objavljeno | 14-05-2021 - 12:15 |

