asgaros Vulnerabilities and Affected Products
Vulnerabilities associated with asgaros_forum.
Products
Clear product- Asgaros Forum4 vulnerabilities
- asgaros_forum2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-5604CRITICAL | Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File UploadThe Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution. | CVSS9.8v3.1 | EPSS1.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24827CRITICAL | Asgaros Forum < 1.15.13 - Unauthenticated SQL InjectionThe Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue | CVSS9.8v3.1 | EPSS13.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |