Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6686-jvr4-7m78

Опубликовано: 10 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

EPSS

Процентиль: 65%
0.00491
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

EPSS

Процентиль: 65%
0.00491
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22