PT-2022-20499 · Plugin · Plugin

Cedric-Anne

·

Published

2022-06-20

·

Updated

2023-04-03

·

CVE-2022-31062

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plugin versions prior to 1.0.2
Description A plugin public script can be used to read the content of system files.
Recommendations For versions prior to 1.0.2, upgrade to version 1.0.2. As a temporary workaround, consider deleting the b/deploy/index.php file if the deploy feature is not used.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-31062
GHSA-Q33F-JCJF-P4V9

Affected Products

Plugin