CVE-2023-5604Code Injection in Forum

Severity
9.8CRITICALNVD
EPSS
7.0%
top 8.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 27

Description

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload2023-11-27
GHSA
GHSA-7862-qcxg-7h4c: The Asgaros Forum WordPress plugin before 22023-11-27
CVE-2023-5604 — Code Injection in Asgaros Forum | cvebase