PT-2022-13960 · WordPress · Amministrazione Aperta
Hassan Khan Yusufzai
+1
·
Published
2022-05-16
·
Updated
2022-10-14
·
CVE-2022-1560
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Amministrazione Aperta WordPress plugin versions prior to 3.8
Description
The issue is related to a Local File Inclusion problem due to the lack of validation of the
open parameter before using it in an include statement. Although initially thought to be exploitable by unauthenticated users, the affected file generates a fatal error when accessed directly, preventing the affected code from being reached. However, exploitation is possible via the dashboard when logged in as an admin or by tricking a logged-in admin into opening a malicious link.Recommendations
For versions prior to 3.8, update to version 3.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the dashboard and limiting the ability of admins to open links from untrusted sources. Avoid using the
open parameter in include statements until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amministrazione Aperta