Description
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 25 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-25T16:20:36.240Z
Reserved: 2023-03-08T15:34:20.038Z
Link: CVE-2023-1273
Updated: 2024-08-02T05:40:59.688Z
Status : Modified
Published: 2023-07-04T08:15:10.123
Modified: 2024-11-21T07:38:48.267
Link: CVE-2023-1273
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.