CVE Database
/

CVE-2022-1560

Back to search

CVE-2022-1560

Published: May 16, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link

VendorProductVersions

Unknown

Amministrazione Aperta

affected
3.8 - < 3.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now