Sploitus

CVE-2021-24347

8 known exploits for CVE-2021-24347

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

Smartypantsplugins Sp Project \& Document Manager
< 4.22
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
54.1% (99th percentile)
Weakness
CWE-178
NVD status
Modified
Published
2021-06-14
CVE-2021-24347 at NVD
Authoritative description, scoring and affected products

8 known exploits for CVE-2021-24347

Proof-of-concept code and exploit modules indexed by Sploitus