Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r57w-p77g-3j43

Опубликовано: 10 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.

EPSS

Процентиль: 90%
0.05785
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.

EPSS

Процентиль: 90%
0.05785
Низкий

8.8 High

CVSS3

Дефекты

CWE-502