Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: postgresql14Packages.pg_squeeze

Found 1 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Squeeze < 1.7.12 - Author+ Arbitrary File Upload

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

References

Affected products

Squeeze
  • <1.7.12

Matching in nixpkgs

Package maintainers