PT-2024-14880 · Unknown · Theme Editor

Dateoljo

+1

·

Published

2024-03-26

·

Updated

2024-03-27

·

CVE-2023-6091

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Theme Editor versions n/a through 2.7.1
Description The issue is related to an Unrestricted Upload of File with Dangerous Type. This allows for the upload of files with potentially dangerous types, which could lead to security issues.
Recommendations For versions n/a through 2.7.1, update to a version that fixes this issue, as the current version allows unrestricted file uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-6091

Affected Products

Theme Editor