cve/2021/CVE-2021-24248.md
2025-09-29 21:09:30 +02:00

18 lines
958 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2021-24248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24248)
![](https://img.shields.io/static/v1?label=Product&message=Business%20Directory%20Plugin%20%E2%80%93%20Easy%20Listing%20Directories%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=5.11.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-434%20Unrestricted%20Upload%20of%20File%20with%20Dangerous%20Type&color=brightgreen)
### Description
The Business Directory Plugin Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE
### POC
#### Reference
- https://wpscan.com/vulnerability/ca886a34-cd2b-4032-9de1-8089b5cf3001
#### Github
- https://github.com/20142995/nuclei-templates