First published: Thu Mar 21 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gesundheit Bewegt GmbH Zippy | <1.6.10 | |
Zippy | >n/a<=1.6.9 | |
WordPress Zippy plugin | <=1.6.9 |
Update to 1.6.10 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27964 is classified as a high-severity vulnerability due to its potential for unrestricted file uploads.
To fix CVE-2024-27964, upgrade Zippy to version 1.6.10 or later.
CVE-2024-27964 allows the upload of files with dangerous types, which could include executable or script files.
CVE-2024-27964 affects Zippy versions from n/a up to 1.6.9.
Yes, the Zippy plugin for WordPress versions up to 1.6.9 is vulnerable to CVE-2024-27964.