CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2021-25082

HIGH
8.8
CVSS Severity Score
EPSS Score0.0890%
EPSS Percentile26.69th
Published2022年2月21日
Last Modified2024年11月21日

Vulnerability Description

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

Affected Platforms (CPE)

📦
Sygnoos

Popup Builder

< 4.0.7

References & Advisories

相關漏洞威脅