Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmr8-fmmf-mpmw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.

In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.

EPSS

Процентиль: 94%
0.14736
Средний

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.

EPSS

Процентиль: 94%
0.14736
Средний

Дефекты

CWE-20