CVE-2023-1427: Photo Gallery by 10Web < 1.8.15 - Admin+ Path Traversal
Published Apr 17, 2023
·Updated
- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
Affected Software
1 affected component
10web Photo Gallery Wordpress<1.8.15
Event History
Apr 17, 2023
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-1427?
CVE-2023-1427 is a vulnerability found in The Photo Gallery by 10Web WordPress plugin before version 1.8.15.
2
What is the severity of CVE-2023-1427?
CVE-2023-1427 has a severity rating of 4.9, which is considered medium.
3
What is the affected software by CVE-2023-1427?
The affected software is the Photo Gallery by 10Web WordPress plugin before version 1.8.15.
4
What is the vulnerability description of CVE-2023-1427?
CVE-2023-1427 allows high privilege users to put images anywhere in the filesystem via a path traversal vector.
5
How can CVE-2023-1427 be fixed?
To fix CVE-2023-1427, update The Photo Gallery by 10Web WordPress plugin to version 1.8.15 or later.