The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-11-27T16:22:01.657Z

Updated: 2024-08-02T07:24:04.609Z

Reserved: 2023-08-10T15:33:52.218Z

Link: CVE-2023-4297

cve-icon Vulnrichment

Updated: 2024-08-02T07:24:04.609Z

cve-icon NVD

Status : Modified

Published: 2023-11-27T17:15:08.563

Modified: 2024-07-12T16:11:19.193

Link: CVE-2023-4297

cve-icon Redhat

No data.