Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-24347

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.814
EPSS Ranking 99.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2021-24347


Contact Us

Shodan ® - All rights reserved