CVE Database /
CVE-2020-36847
CVE · Critical
CVE-2020-36847 — Simple File List [simple-file-list] < 4.2.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-36847
|
Simple File List [simple-file-list] < 4.2.3 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.8
|
< 4.2.3
|
4.2.3 |
2020-11-02 |
—
|
CVE-2020-36847
The Simple File List plugin through version 4.2.2 contains a remote code execution vulnerability in its rename functionality that permits unauthenticated users to execute arbitrary code on the server. An attacker can exploit this by renaming uploaded files with a .png extension to use a .php extension instead, allowing the execution of malicious PHP code. This flaw was fixed in version 4.2.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings