First published: Fri May 17 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Supsystic Popup | <=1.10.19 | |
WordPress Popup by Supsystic | <1.10.20 |
Update to 1.10.20 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46197 is classified as a medium severity vulnerability due to its potential for exploitation through path traversal.
To fix CVE-2023-46197, update the Popup by Supsystic plugin to version 1.10.20 or later.
CVE-2023-46197 affects the Popup by Supsystic plugin versions up to and including 1.10.19.
CVE-2023-46197 is a Path Traversal vulnerability that allows unauthorized access to files outside of intended directories.
Yes, CVE-2023-46197 can be exploited remotely by attackers to gain access to sensitive files.