Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h2r-h2x2-mg4h

Опубликовано: 30 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

EPSS

Процентиль: 30%
0.00109
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 2.7
nvd
больше 2 лет назад

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

EPSS

Процентиль: 30%
0.00109
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22