Описание
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6 (исключая)
cpe:2.3:a:themeeditor:theme_editor:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 68%
0.00576
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-552
CWE-552
Связанные уязвимости
github
больше 3 лет назад
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
EPSS
Процентиль: 68%
0.00576
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-552
CWE-552