CVE-2021-24347
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".
- Affected products
- Sp Project & Document Manager
- Smartypantsplugins Sp Project \& Document Manager
- < 4.22
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 54.1% (99th percentile)
- Weakness
- CWE-178
- NVD status
- Modified
- Published
- 2021-06-14
CVE-2021-24347 at NVD
8 known exploits for CVE-2021-24347
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
WordPress SP Project And Document Remote Code Execution Exploit
WordPress SP Project And Document Remote Code Execution
Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated)
Wordpress SP Project & Document Manager 4.21 Plugin - Remote Code Execution Exploit
WordPress SP Project And Document Manager 4.21 Shell Upload
Wordpress Plugin SP Project and Document - Authenticated Remote Code Execution
SP Project & Document Manager < 4.22 - Authenticated Shell Upload