Point Maker Includes Remote File Inclusion Vulnerability
CVE-2024-49317
7.5HIGH
Key Information:
- Vendor
- Zipang
- Status
- Point Maker
- Vendor
- CVE Published:
- 17 October 2024
Summary
An improper control of filename for Include/Require statement vulnerability exists in the ZIPANG Point Maker plugin, which allows attackers to exploit PHP Local File Inclusion. This security flaw enables unauthorized users to include files from the server's filesystem, potentially leading to unauthorized access and the execution of malicious code. The vulnerability affects all versions from n/a to 0.1.4, making it crucial for users of the Point Maker plugin to assess their environment and apply remedial measures to secure their applications.
Affected Version(s)
Point Maker <= 0.1.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
theviper17 (Patchstack Alliance)