The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:40:03.785Z
Reserved: 2022-02-28T00:00:00
Link: CVE-2022-0779
No data.
Status : Modified
Published: 2022-06-08T10:15:09.017
Modified: 2024-11-21T06:39:22.847
Link: CVE-2022-0779
No data.
OpenCVE Enrichment
No data.
Weaknesses