Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h2r-h2x2-mg4h

Опубликовано: 30 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

EPSS

Процентиль: 49%
0.00665
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 2.7
nvd
около 3 лет назад

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

EPSS

Процентиль: 49%
0.00665
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22