Severity
8.1HIGH
EPSS
0.2%
top 62.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6

Description

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Awesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion2023-11-06
GHSA
GHSA-x85w-8f7w-627g: The Awesome Support WordPress plugin before 62023-11-06
CVE-2023-5355 (HIGH CVSS 8.1) | The Awesome Support WordPress plugi | cvebase.io