First published: Fri Feb 15 2019(Updated: )
Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.
Credit: larry0@me.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy2map Photos | =1.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-4617 is considered to be high due to its potential for unauthorized file access.
To fix CVE-2015-4617, update the Easy2map-photos WordPress Plugin to the latest version that addresses the path traversal vulnerability.
CVE-2015-4617 affects Easy2map-photos WordPress Plugin version 1.09.
CVE-2015-4617 is a path traversal vulnerability that allows attackers to write files outside of designated directories.
Attackers can exploit CVE-2015-4617 by manipulating file names to gain unauthorized access to files on the server.