Path Traversal Vulnerability Affects Consulting Elementor Widgets
CVE-2024-37092
8.8HIGH
Summary
A vulnerability exists in the Consulting Elementor Widgets developed by StylemixThemes due to improper limitation of a pathname to a restricted directory. This security issue allows for local file inclusion, which could potentially lead to unauthorized access to sensitive files on the server. This flaw impacts multiple versions of the Consulting Elementor Widgets, specifically ranging from n/a to version 1.3.0, and underscores the need for users to apply necessary patches to safeguard their applications from exploitation.
Affected Version(s)
Consulting Elementor Widgets <= 1.3.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)