Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvp8-6wrp-jww8

Опубликовано: 16 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

EPSS

Процентиль: 98%
0.46274
Средний

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
около 3 лет назад

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

EPSS

Процентиль: 98%
0.46274
Средний

9.1 Critical

CVSS3

Дефекты

CWE-22