Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw49-5g4r-c94w

Опубликовано: 01 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

EPSS

Процентиль: 54%
0.00308
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.1
nvd
10 месяцев назад

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

EPSS

Процентиль: 54%
0.00308
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-22