Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-792m-27mh-cxj5

Опубликовано: 27 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the plugin should allow.

The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the plugin should allow.

EPSS

Процентиль: 68%
0.00563
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
почти 2 года назад

The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the plugin should allow.

CVSS3: 2.7
fstec
почти 2 года назад

Уязвимость плагина BackUpWordPress системы управления содержимым сайта WordPress, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 68%
0.00563
Низкий

2.7 Low

CVSS3