Path Traversal Vulnerability Affects All In One Favicon
CVE-2023-24416
6.5MEDIUM
Summary
A path traversal vulnerability exists in All In One Favicon due to improper limitation when handling pathname inputs. This flaw enables attackers to manipulate file paths, potentially allowing access to sensitive files stored on the server. If exploited, it could lead to unauthorized file reading or deletion, which poses a significant risk to the security and integrity of web applications utilizing the affected plugin versions. Protecting against this vulnerability requires ensuring proper validation and sanitization of user inputs related to file paths.
Affected Version(s)
All In One Favicon <= 4.7
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)