FlatPress File Delete panel.mediamanager.file.php doItemActions path traversal
Published Dec 27, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.87%
Description
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is 5d5c7f6d8f072d14926fc2c3a97cdd763802f170. It is recommended to apply a patch to fix this issue. The identifier VDB-216861 was assigned to this vulnerability.
Affected products
- Vendor n/a Product FlatPress Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | FlatPress | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52046 Advisory
- https://github.com/flatpressblog/flatpress/commit/5d5c7f6d8f072d14926fc2c3a97cdd763802f170 patchThird Party Advisory
- https://github.com/flatpressblog/flatpress/issues/179 issue-trackingIssue TrackingPatchThird Party Advisory
- https://vuldb.com/?ctiid.216861 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.216861 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52046 | Advisory | |
| https://github.com/flatpressblog/flatpress/commit/5d5c7f6d8f072d14926fc2c3a97cdd763802f170 | patchThird Party Advisory | |
| https://github.com/flatpressblog/flatpress/issues/179 | issue-trackingIssue TrackingPatchThird Party Advisory | |
| https://vuldb.com/?ctiid.216861 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.216861 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.