Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3vp-3p2j-8q53

Опубликовано: 10 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

EPSS

Процентиль: 85%
0.02455
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 года назад

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

EPSS

Процентиль: 85%
0.02455
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22