PT-2024-35213 · Cmsminds · Cmsminds Boat Rental Plugin For Wordpress

Stealthcopter

·

Published

2024-11-14

·

Updated

2024-11-15

·

CVE-2024-52376

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cmsMinds Boat Rental Plugin for WordPress versions 1.0.1 and earlier
Description The issue allows malicious file uploads, posing a risk of web server compromise. This can enable an attacker to upload a web shell to a web server.
Recommendations For versions 1.0.1 and earlier, update to version 1.0.2 to stay secure. As a temporary workaround, consider restricting file uploads until the issue is resolved.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-52376

Affected Products

Cmsminds Boat Rental Plugin For Wordpress