Логотип exploitDog
bind:CVE-2022-2554
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-2554

Количество 2

Количество 2

nvd логотип

CVE-2022-2554

больше 3 лет назад

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-pr9x-p233-rm4x

больше 3 лет назад

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-2554

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pr9x-p233-rm4x

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

CVSS3: 4.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу