Описание
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Ссылки
- Broken Link
- Product
- Patch
- Product
- Broken Link
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0 (исключая)
cpe:2.3:a:zishanj:gi-media-library:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 98%
0.48596
Средний
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
7 месяцев назад
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
EPSS
Процентиль: 98%
0.48596
Средний
7.5 High
CVSS3
Дефекты
CWE-22