Description
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33638 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root. |
References
History
Fri, 10 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-10T20:55:18.959Z
Reserved: 2023-04-17T12:36:12.389Z
Link: CVE-2023-2117
Updated: 2024-08-02T06:12:20.449Z
Status : Modified
Published: 2023-05-30T08:15:09.963
Modified: 2025-01-10T21:15:11.273
Link: CVE-2023-2117
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD