First published: Fri Dec 06 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Roninwp Revy allows Upload a Web Shell to a Web Server.This issue affects Revy: from n/a through 1.18.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
RoninWP Revy | >n/a<=1.18 | |
RoninWP Revy | <=1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54214 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2024-54214, update the Roninwp Revy plugin to version 1.19 or later.
CVE-2024-54214 allows an attacker to upload a web shell to the web server, compromising the system.
CVE-2024-54214 affects Roninwp Revy versions from n/a up to and including 1.18.
CVE-2024-54214 is common among web applications that improperly handle file uploads, especially in WordPress plugins.