Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2023-1427
Published:
Apr 17, 2023
| Modified:
Nov 07, 2023
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2023-1427
CWE
https://cwe.mitre.org/data/definitions/.html
The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
Affected Software
Name
Vendor
Start Version
End Version
Photo_gallery
10web
*
1.8.15 (excluding)
References
https://wpscan.com/vulnerability/c8917ba2-4cb3-4b09-8a49-b7c612254946
Aqua Container Security