diff --git a/cves/2021/CVE-2021-24947.yaml b/cves/2021/CVE-2021-24947.yaml index 30f3484f54..248db03bae 100644 --- a/cves/2021/CVE-2021-24947.yaml +++ b/cves/2021/CVE-2021-24947.yaml @@ -6,7 +6,7 @@ info: severity: high description: The plugin does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server. reference: - - https://wpscan.com/vulnerability/cb232354-f74d-48bb-b437-7bdddd1df42a + - https://wpscan.com/vulnerability/c6bb12b1-6961-40bd-9110-edfa9ee41a18 - https://nvd.nist.gov/vuln/detail/CVE-2021-24947 classification: cve-id: CVE-2021-24947