PT-2018-18062 · Unknown · Site Editor
Nicolas Buzy-Debat
·
Publicado
2018-03-19
·
Atualizado
2020-08-24
·
CVE-2018-7422
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Site Editor plugin versions prior to 1.2.0
Description
A Local File Inclusion issue allows remote attackers to retrieve arbitrary files via the
ajax path parameter to "editor/extensions/pagebuilder/includes/ajax shortcode pattern.php". This is an example of absolute path traversal.Recommendations
For Site Editor plugin versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "editor/extensions/pagebuilder/includes/ajax shortcode pattern.php" file until a patch is available. Avoid using the
ajax path parameter in the affected endpoint until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Site Editor