vendor:
GraceMedia Media Player
by:
Manuel García Cárdenas
9.8
CVSS
CRITICAL
Local File Inclusion
98
CWE
Product Name: GraceMedia Media Player
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: CVE-2019-9618
CPE: a:gracemedia:gracemedia_media_player
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
WordPress Plugin GraceMedia Media Player 1.0 – Local File Inclusion
This bug was found in the file: /gracemedia-media-player/templates/files/ajax_controller.php. The parameter "cfg" it is not sanitized allowing include local files. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application.
Mitigation:
Disable plugin until a fix is available, vendor does not fix after 2 requests.