PT-2023-32235 · Undefined · Undefined

CVE-2023-5646

·

Publicado

2023-10-20

·

Atualizado

2024-01-23

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
‼ CVE-2023-5646 ‼
The AI ChatBot for WordPress is vulnerable to Directory Traversal in version 4.9.2 via the qcld openai upload pagetraining file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php. This vulnerability is the same as CVE-2023-5241, but was reintroduced in version 4.9.2.
📖 Read
via "National Vulnerability Database".
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-5646

Produtos afetados

Undefined