vendor:
Paypal Currency Converter Basic For Woocommerce
by:
Kuroi'SH
7.5
CVSS
HIGH
File Read
22
CWE
Product Name: Paypal Currency Converter Basic For Woocommerce
Affected Version From: 1
Affected Version To: 1.3
Patch Exists: NO
Related CWE: N/A
CPE: a:wordpress:paypal_currency_converter_basic_for_woocommerce
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
Paypal Currency Converter Basic For Woocommerce File Read
Based on user input, the content of a file is printed out (unfortunately not included) so any html file can be loaded, and an attacker may be able to read any local file which is not executed in the server.
Mitigation:
Ensure that user input is properly sanitized and validated before being used to access files.