First published: Tue Dec 27 2022(Updated: )
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is 5d5c7f6d8f072d14926fc2c3a97cdd763802f170. It is recommended to apply a patch to fix this issue. The identifier VDB-216861 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4748 has been classified as critical.
To fix CVE-2022-4748, update to the latest version of FlatPress where the vulnerability is patched.
CVE-2022-4748 affects the File Delete Handler in the doItemActions function of the media manager plugin.
CVE-2022-4748 can be exploited through the manipulation of the deletefile argument.
Yes, if your FlatPress installation is outdated, it is likely vulnerable to CVE-2022-4748.