The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-11-27T16:22:01.657Z
Updated: 2024-08-02T07:24:04.609Z
Reserved: 2023-08-10T15:33:52.218Z
Link: CVE-2023-4297
Vulnrichment
Updated: 2024-08-02T07:24:04.609Z
NVD
Status : Modified
Published: 2023-11-27T17:15:08.563
Modified: 2024-11-21T08:34:48.470
Link: CVE-2023-4297
Redhat
No data.