Описание
- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.8.15 (исключая)
cpe:2.3:a:10web:photo_gallery:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 33%
0.00134
Низкий
4.9 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 4.9
github
почти 3 года назад
- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
EPSS
Процентиль: 33%
0.00134
Низкий
4.9 Medium
CVSS3