WordPress 的“Multi Uploader for Gravity Forms”插件在所有版本(包括 1.1.9 及更早版本)中均存在任意文件上传漏洞,漏洞源于 函数。该漏洞是由于在处理分块上传(chunked upload)过程中,对文件类型验证不足所致。这使得未认证的攻击者能够上传任意文件到受影响网站的服务器上,进而可能导致远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sh1zen | Multi Uploader for Gravity Forms | 0 ~ 1.1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet