CVE-2019-15648
- EPSS 0.63%
- Veröffentlicht 27.08.2019 12:15:13
- Zuletzt bearbeitet 21.11.2024 04:29:11
- CVE-Watchlists
- Unerledigt
Insert or Embed Articulate Content into WordPress < 4.29991 - Directory Traversal
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.452 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:P
|
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.