Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6467

Опубликовано: 17 июл. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in all versions up to, and including, 1.1.5 via the 'bookingpress_save_lite_wizard_settings_func' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files that contain the content of files on the server, allowing the execution of any PHP code in those files or the exposure of sensitive information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:reputeinfosystems:bookingpress:*:*:*:*:*:wordpress:*:*
Версия до 1.1.6 (исключая)

EPSS

Процентиль: 78%
0.01093
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
github
больше 1 года назад

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in all versions up to, and including, 1.1.5 via the 'bookingpress_save_lite_wizard_settings_func' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files that contain the content of files on the server, allowing the execution of any PHP code in those files or the exposure of sensitive information.

EPSS

Процентиль: 78%
0.01093
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo