CVE-2013-20002

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
17/06/2021
Last modified:
23/06/2021

Description

Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:themify:framework:*:*:*:*:*:*:*:* 1.2.2 (excluding)