CVE-2023-5414: Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the showeslogs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to other sites, for example in shared hosting environments.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5414?
CVE-2023-5414 is a vulnerability in the Icegram Express plugin for WordPress that allows administrator-level attackers to read the contents of arbitrary files on the server.
How severe is CVE-2023-5414?
CVE-2023-5414 has a severity rating of 9.1 (Critical).
Which version of the Icegram Express plugin for WordPress is affected by CVE-2023-5414?
Versions up to and including 5.6.23 of the Icegram Express plugin for WordPress are affected by CVE-2023-5414.
What is the CWE ID associated with CVE-2023-5414?
The CWE ID associated with CVE-2023-5414 is 22.
How can an attacker exploit CVE-2023-5414?
An attacker can exploit CVE-2023-5414 by using the show_es_logs function to perform a Directory Traversal attack and read the contents of arbitrary files on the server.