PT-2018-16871 · WordPress · Gd Rating System

CVE-2018-5290

·

Published

2018-01-08

·

Updated

2018-01-19

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GD Rating System plugin version 2.3
Description The issue concerns a Directory Traversal problem in the wp-admin/admin.php panel, specifically affecting the gd-rating-system-transfer page. This is related to a parameter in the wp-admin/admin.php panel for the gd-rating-system-transfer page.
Recommendations For GD Rating System plugin version 2.3, consider restricting access to the gd-rating-system-transfer page in the wp-admin/admin.php panel until a patch is available. As a temporary workaround, avoid using the vulnerable parameter in the affected page.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5290

Affected Products

Gd Rating System