vendor:
cab-fare-calculator
by:
Hassan Khan Yusufzai - Splint3r7
8.8
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: cab-fare-calculator
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: YES
Related CWE:
CPE: a:wordpress:wordpress_plugin:cab-fare-calculator
Platforms Tested: Firefox
2022
WordPress Plugin cab-fare-calculator 1.0.3 – Local File Inclusion
The vulnerability exists due to insufficient sanitization of user-supplied input in the 'controller' parameter of the 'tblight.php' script. A remote attacker can send a specially crafted request to the vulnerable script and execute arbitrary PHP code on the target system.
Mitigation:
The vendor recommends to update the plugin to the latest version. Additionally, the user should ensure that all input is properly sanitized before being used.