Error Log Viewer Plugin <= 1.1.1 - Admin+ Arbitrary File Clearing
CVE-2021-24966

4.9MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
14 March 2022

Summary

The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

Affected Version(s)

Error Log Viewer by BestWebSoft 1.1.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ceylan Bozogullarindan
.