Description
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:40:03.785Z
Reserved: 2022-02-28T00:00:00.000Z
Link: CVE-2022-0779
No data.
Status : Modified
Published: 2022-06-08T10:15:09.017
Modified: 2024-11-21T06:39:22.847
Link: CVE-2022-0779
No data.
OpenCVE Enrichment
No data.
Weaknesses