CVE-2023-38399: WordPress Phlox Portfolio plugin <= 2.3.1 - Unauthenticated Local File Inclusion vulnerability
Published May 17, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Portfolio allows PHP Local File Inclusion.This issue affects Phlox Portfolio: from n/a through 2.3.1.
Affected Software
2 affected components
averta Phlox Portfolio>=undefined
WordPress Phlox Portfolio<=2.3.1
Remediation
Information
Update to 2.3.2 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:52 AM
Data Sourced
via MITRE·06:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-38399?
CVE-2023-38399 is classified as a high-severity vulnerability due to its potential for PHP Local File Inclusion.
2
How do I fix CVE-2023-38399?
To resolve CVE-2023-38399, update Averta Phlox Portfolio to version 2.3.2 or higher.
3
What are the affected versions for CVE-2023-38399?
CVE-2023-38399 affects Averta Phlox Portfolio versions from n/a through 2.3.1.
4
What impact does CVE-2023-38399 have on my site?
CVE-2023-38399 can allow an attacker to include files from the server, potentially leading to unauthorized access to sensitive information.
5
Is authentication required to exploit CVE-2023-38399?
CVE-2023-38399 can be exploited without authentication, making it particularly dangerous for sites using vulnerable versions.