Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.
History

Thu, 31 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-829
CPEs cpe:2.3:a:buynowdepot:advanced_online_ordering_and_delivery_platform:*:*:*:*:*:wordpress:*:*

Mon, 28 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Buynowdepot
Buynowdepot advanced Online Ordering And Delivery Platform
CPEs cpe:2.3:a:buynowdepot:advanced_online_ordering_and_delivery_platform:*:*:*:*:*:*:*:*
Vendors & Products Buynowdepot
Buynowdepot advanced Online Ordering And Delivery Platform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Oct 2024 13:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.
Title WordPress Advanced Online Ordering and Delivery Platform plugin <= 2.0.0 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-10-28T12:35:15.336Z

Updated: 2024-10-28T18:41:32.661Z

Reserved: 2024-10-24T07:26:59.133Z

Link: CVE-2024-50497

cve-icon Vulnrichment

Updated: 2024-10-28T18:41:11.807Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-28T13:15:07.200

Modified: 2024-10-31T13:55:14.493

Link: CVE-2024-50497

cve-icon Redhat

No data.