Path Traversal Vulnerability Affects All In One Favicon
CVE-2023-24416

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
23 February 2024

Summary

A path traversal vulnerability exists in All In One Favicon due to improper limitation when handling pathname inputs. This flaw enables attackers to manipulate file paths, potentially allowing access to sensitive files stored on the server. If exploited, it could lead to unauthorized file reading or deletion, which poses a significant risk to the security and integrity of web applications utilizing the affected plugin versions. Protecting against this vulnerability requires ensuring proper validation and sanitization of user inputs related to file paths.

Affected Version(s)

All In One Favicon <= 4.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.