Описание
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
Ссылки
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.4.0.1 (исключая)
cpe:2.3:a:piwigo:localfiles_editor:*:*:*:*:*:piwigo:*:*
EPSS
Процентиль: 39%
0.00176
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-345
Связанные уязвимости
github
больше 3 лет назад
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
EPSS
Процентиль: 39%
0.00176
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-345