- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-04-17T12:17:41.603Z

Updated: 2023-04-17T12:17:41.603Z

Reserved: 2023-03-16T10:39:16.489Z


Link: CVE-2023-1427

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-04-17T13:15:38.440

Modified: 2023-11-07T04:03:34.490


Link: CVE-2023-1427

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.