InBoundio Marketing < 2.0.1 - Arbitrary File Upload
criticalThe InBoundio Marketing plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the csv_uploader.php file in versions before 2.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code executio...
- CVSS:
- 9.8
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Mar 24, 2015