Path Traversal Vulnerability Affects All In One Favicon
CVE-2023-24416
6.5MEDIUM
What is CVE-2023-24416?
A path traversal vulnerability exists in All In One Favicon due to improper limitation when handling pathname inputs. This flaw enables attackers to manipulate file paths, potentially allowing access to sensitive files stored on the server. If exploited, it could lead to unauthorized file reading or deletion, which poses a significant risk to the security and integrity of web applications utilizing the affected plugin versions. Protecting against this vulnerability requires ensuring proper validation and sanitization of user inputs related to file paths.
Affected Version(s)
All In One Favicon <= 4.7