CVE-2023-46197: WordPress Popup by Supsystic plugin <= 1.10.19 - Unauthenticated Subscriber Email Addresses Disclosure
Published May 17, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.
Affected Software
2 affected components
Supsystic Popup by Supsystic<=1.10.19
Supsystic Popup Wordpress<1.10.20
Remediation
Information
Update to 1.10.20 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:33 AM
Data Sourced
via MITRE·08:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46197?
CVE-2023-46197 is classified as a medium severity vulnerability due to its potential for exploitation through path traversal.
2
How do I fix CVE-2023-46197?
To fix CVE-2023-46197, update the Popup by Supsystic plugin to version 1.10.20 or later.
3
What software is affected by CVE-2023-46197?
CVE-2023-46197 affects the Popup by Supsystic plugin versions up to and including 1.10.19.
4
What type of vulnerability is CVE-2023-46197?
CVE-2023-46197 is a Path Traversal vulnerability that allows unauthorized access to files outside of intended directories.
5
Can CVE-2023-46197 be exploited remotely?
Yes, CVE-2023-46197 can be exploited remotely by attackers to gain access to sensitive files.