CVE-2023-5355: Awesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion
Published Nov 6, 2023
·Updated
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
Affected Software
1 affected component
Getawesomesupport Awesome Support Wordpress<6.1.5
Event History
Nov 6, 2023
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5355.
2
What is the title of this vulnerability?
The title of this vulnerability is Awesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion.
3
What is the impact of this vulnerability?
This vulnerability allows a ticket submitter to delete arbitrary files on the server.
4
What is the severity level of CVE-2023-5355?
The severity level of CVE-2023-5355 is high (8.1).
5
How can I fix this vulnerability?
To fix this vulnerability, update the Awesome Support WordPress plugin to version 6.1.5 or later.