CVE Database
/

CVE-2021-24549

Back to search

CVE-2021-24549

Published: Aug 23, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths before using it in various actions, such as to read arbitrary files from the server. This allows high privilege users such as administrator to access any file on the web server outside of the blog directory via a path traversal attack.

VendorProductVersions

Unknown

AceIDE

affected
2.6.2 - <= 2.6.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now