PT-2024-11727 · Unknown · Wp-Formassembly

Nguyen Anh Tien

·

Published

2024-04-24

·

Updated

2024-04-24

·

CVE-2022-45852

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP-FormAssembly versions n/a through 2.0.5
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a Path Traversal vulnerability. This vulnerability allows Path Traversal in FormAssembly / Drew Buschhorn WP-FormAssembly.
Recommendations For WP-FormAssembly versions n/a through 2.0.5, update to a version later than 2.0.5 to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-45852

Affected Products

Wp-Formassembly