vendor:
Error Log Viewer
by:
Ceylan Bozogullarindan
4.9
CVSS
MEDIUM
Arbitrary File Clearing
22
CWE
Product Name: Error Log Viewer
Affected Version From: 1.1.2001
Affected Version To: 1.1.2001
Patch Exists: YES
Related CWE: CVE-2021-24966
CPE: a:wordpress_plugin:error_log_viewer:1.1.1
Platforms Tested: Linux
2021
WordPress Plugin Error Log Viewer 1.1.1 – Arbitrary File Clearing (Authenticated)
The value of a file path which is going to be deleted is not properly and sufficiently controlled. The parameter 'rrrlgvwr_clear_file_name' can be manipulated only by authenticated users.
Mitigation:
Update to the latest version of the plugin. Limit access to the 'rrrlgvwr_clear_file_name' parameter to trusted authenticated users only.