Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4101

Опубликовано: 16 янв. 2023
Источник: nvd
CVSS3: 9.1
EPSS Средний

Описание

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:images_optimize_and_upload_cf7_project:images_optimize_and_upload_cf7:*:*:*:*:*:wordpress:*:*
Версия до 2.1.4 (включая)

EPSS

Процентиль: 97%
0.43865
Средний

9.1 Critical

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 9.1
github
около 3 лет назад

The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.

EPSS

Процентиль: 97%
0.43865
Средний

9.1 Critical

CVSS3

Дефекты