vendor:
amministrazione-aperta
by:
Hassan Khan Yusufzai - Splint3r7
8.8
CVSS
HIGH
Local File Inclusion (LFI)
98
CWE
Product Name: amministrazione-aperta
Affected Version From: 3.7.2003
Affected Version To: 3.7.2003
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Firefox
2022
WordPress Plugin amministrazione-aperta 3.7.3 – Local File Read – Unauthenticated
The WordPress Plugin amministrazione-aperta version 3.7.3 is vulnerable to Local File Inclusion (LFI). An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable file dispatcher.php with the parameter 'open' set to the path of the file to be included. This can allow the attacker to read sensitive files from the server.
Mitigation:
Upgrade to the latest version of the WordPress Plugin amministrazione-aperta.