Description
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:40:03.785Z
Reserved: 2022-02-28T00:00:00.000Z
Link: CVE-2022-0779
No data.
Status : Modified
Published: 2022-06-08T10:15:09.017
Modified: 2024-11-21T06:39:22.847
Link: CVE-2022-0779
No data.
OpenCVE Enrichment
No data.
Weaknesses