Количество 3
Количество 3
CVE-2023-1273
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
GHSA-jgrp-j9c7-qv87
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
BDU:2023-06186
Уязвимость плагина ND Shortcodes системы управления содержимым сайта WordPress, позволяющая нарушителю выполнять LFI-атаки
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-1273 The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | CVSS3: 8.8 | 11% Средний | больше 2 лет назад | |
GHSA-jgrp-j9c7-qv87 The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | CVSS3: 8.8 | 11% Средний | больше 2 лет назад | |
BDU:2023-06186 Уязвимость плагина ND Shortcodes системы управления содержимым сайта WordPress, позволяющая нарушителю выполнять LFI-атаки | CVSS3: 8.8 | 11% Средний | больше 2 лет назад |
Уязвимостей на страницу