First published: Mon Nov 06 2023(Updated: )
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Awesome Support | <6.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-5355.
The title of this vulnerability is Awesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion.
This vulnerability allows a ticket submitter to delete arbitrary files on the server.
The severity level of CVE-2023-5355 is high (8.1).
To fix this vulnerability, update the Awesome Support WordPress plugin to version 6.1.5 or later.