Directory Traversal Vulnerability in NextGEN Gallery for WordPress
CVE-2015-9538
6.5MEDIUM
Summary
The NextGEN Gallery plugin for WordPress, prior to version 2.1.15, contains a directory traversal vulnerability that enables attackers to access files and directories outside of the intended scope. This vulnerability allows unauthorized file access through the manipulation of the file path, potentially leading to sensitive data exposure. Users of affected versions are strongly advised to update to the latest version to mitigate the risk of exploitation.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved