8.6

CVE-2024-13617

Exploit

Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated Arbitrary File Download

Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated Arbitrary File Download

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server
Mögliche Gegenmaßnahme
Downloable by American Osteopathic Association: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OsteopathicDownloadable By American Osteopathic Association SwPlatformwordpress Version <= 0.1.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Downloable by American Osteopathic Association
Version *-0.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.354
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/8d6dd979-21ef-4d14-9c42-bbd1d7b65c53/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/3e0b66b9-2e33-41e0-a024-35574716c91d
Third Party Advisory