Описание
The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.
EPSS
Процентиль: 23%
0.00078
Низкий
6.6 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 6.6
github
2 месяца назад
The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.
EPSS
Процентиль: 23%
0.00078
Низкий
6.6 Medium
CVSS3
Дефекты
CWE-22