Directory Traversal Vulnerability in Real3D FlipBook Lite Plugin for WordPress
CVE-2016-10965

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
16 September 2019

Summary

The Real3D FlipBook Lite plugin version 1.0 for WordPress contains a directory traversal vulnerability that allows attackers to manipulate the 'deleteBook' parameter. By exploiting this flaw, unauthorized users may gain access to delete files from the server, potentially compromising sensitive data and the integrity of the web application. This vulnerability highlights the importance of securing user input and implementing proper validation measures.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.