Point Maker Includes Remote File Inclusion Vulnerability
CVE-2024-49317
7.5HIGH
What is CVE-2024-49317?
An improper control of filename for Include/Require statement vulnerability exists in the ZIPANG Point Maker plugin, which allows attackers to exploit PHP Local File Inclusion. This security flaw enables unauthorized users to include files from the server's filesystem, potentially leading to unauthorized access and the execution of malicious code. The vulnerability affects all versions from n/a to 0.1.4, making it crucial for users of the Point Maker plugin to assess their environment and apply remedial measures to secure their applications.
Affected Version(s)
Point Maker <= 0.1.4