Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-728f-qcc4-8q48

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

EPSS

Процентиль: 88%
0.0399
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
больше 4 лет назад

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

EPSS

Процентиль: 88%
0.0399
Низкий

Дефекты

CWE-22