Awesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion
CVE-2023-5355
8.1HIGH
Summary
The Awesome Support plugin prior to version 6.1.5 for WordPress is susceptible to a vulnerability where it fails to sanitize file paths when removing temporary attachment files. This flaw enables attackers with ticket submission capabilities to potentially delete arbitrary files from the server. Such a weakness can lead to significant security risks, including data loss and server compromise.
Affected Version(s)
Awesome Support 0 < 6.1.5
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Sanford
WPScan