Path traversal in Insert or Embed Articulate Content into WordPress - #VU18970

 

Path traversal in Insert or Embed Articulate Content into WordPress - #VU18970

Published: July 3, 2019 / Updated: July 16, 2019


Vulnerability identifier: #VU18970
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in "wp_ajax_del_dir()" and "wp_ajax_rename_dir()" AJAX methods. A remote attacker with subscriber role can send a specially crafted HTTP request and delete and rename arbitrary folders on the system.

Note, this vulnerability can be exploited via CSRF vector.


Affected software

Insert or Embed Articulate Content into WordPress

Remediation

Install updates from vendor's website.

Insert or Embed Articulate Content into WordPress - update to 4.29991

External References

Related Security Bulletins