WordPress EduAdmin Booking plugin <= 5.2.0 - Local File Inclusion vulnerability
CVE-2024-54373

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 December 2024

What is CVE-2024-54373?

A vulnerability exists in EduAdmin Booking, developed by MultiNet Interactive AB, due to improper limitations on pathname access to restricted directories. This path traversal issue could allow attackers to exploit PHP Local File Inclusion, potentially leading to unauthorized file access on the server. The affected versions range from n/a up to 5.2.0, underscoring the necessity for users to promptly update their installations to prevent potential exploitation.

Affected Version(s)

EduAdmin Booking 0 <= 5.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.