PT-2023-16772 · WordPress · Shopping Cart & Ecommerce Store
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Shopping Cart & eCommerce Store WordPress plugin versions prior to 5.4.3
Description
The issue allows authenticated users with admin privileges to perform Local File Inclusion (LFI) attacks due to a lack of validation of HTTP requests. LFI attacks involve tricking an application into accessing or including files on the server that it should not, potentially leading to sensitive information disclosure or code execution.
Recommendations
For versions prior to 5.4.3, update to version 5.4.3 or later to resolve the issue. As a temporary workaround, consider restricting admin privileges to trusted users only until the update can be applied.
Exploit
Correção
Files Accessible to External Parties
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Shopping Cart & Ecommerce Store