The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11878 | The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:49:14.380Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24966
No data.
Status : Modified
Published: 2022-03-14T15:15:08.760
Modified: 2024-11-21T05:54:06.073
Link: CVE-2021-24966
No data.
OpenCVE Enrichment
No data.
EUVD