CVE-2023-5646: Path Traversal
Rejected reason: REJECT DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5241. Reason: This record is a reservation duplicate of CVE-2023-5241. Notes: All CVE users should reference CVE-2023-5241 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.
Other sources
The AI ChatBot for WordPress is vulnerable to Directory Traversal in version 4.9.2 via the qcldopenaiuploadpagetrainingfile function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php. This vulnerability is the same as CVE-2023-5241, but was reintroduced in version 4.9.2.
Affected Software
Event History
Frequently Asked Questions
What should I do regarding CVE-2023-5646?
You should ignore CVE-2023-5646 and refer to CVE-2023-5241 for relevant information.
Is CVE-2023-5646 a significant vulnerability?
CVE-2023-5646 has been marked as a duplicate and is not meant to be used.
What software is affected by CVE-2023-5646?
CVE-2023-5646 pertains to the AI ChatBot WordPress Plugin version 4.9.2.
Can I obtain more details on CVE-2023-5646?
Since CVE-2023-5646 is a rejected record, all inquiries should be directed to CVE-2023-5241 for detailed information.
How do I ensure I am protected against the issues related to CVE-2023-5646?
To mitigate risks associated with CVE-2023-5646, always refer to and apply the patches or recommendations provided for CVE-2023-5241.