- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23680 | - The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 06 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-06T15:29:34.944Z
Reserved: 2023-03-16T10:39:16.489Z
Link: CVE-2023-1427
Updated: 2024-08-02T05:49:11.507Z
Status : Modified
Published: 2023-04-17T13:15:38.440
Modified: 2025-02-06T16:15:32.867
Link: CVE-2023-1427
No data.
OpenCVE Enrichment
No data.
EUVD