CVE-2022-3762

CWE-22Path Traversal3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.8%
top 26.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21

Description

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the server even when they are not supposed to be able to (for example in multisite)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-65wp-vh9q-f2vh: The Booster for WooCommerce WordPress plugin before 52022-11-21
CVEList
Booster for WooCommerce - ShopManager+ Arbitrary File Download2022-11-21
CVE-2022-3762 (MEDIUM CVSS 6.5) | The Booster for WooCommerce WordPre | cvebase.io