First published: Tue Aug 13 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mage-people Event Manager And Tickets Selling Plugin For Woocommerce | <4.2.2 |
Update to 4.2.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43138 has a medium severity due to its potential for PHP Local File Inclusion through path traversal.
To fix CVE-2024-43138, update the Event Manager for WooCommerce plugin to version 4.2.2 or later.
CVE-2024-43138 affects versions of Event Manager for WooCommerce from n/a through 4.2.1.
CVE-2024-43138 is an improper limitation of a pathname to a restricted directory vulnerability, specifically a path traversal issue.
Users of the MagePeople Event Manager and Tickets Selling for WooCommerce plugin, specifically versions prior to 4.2.2, are impacted by CVE-2024-43138.