- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/c8917ba2-4cb3-4b09-8a49-b7c612254946 | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/c8917ba2-4cb3-4b09-8a49-b7c612254946 | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:39
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://wpscan.com/vulnerability/c8917ba2-4cb3-4b09-8a49-b7c612254946 - Exploit, Third Party Advisory | 
07 Nov 2023, 04:03
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | 
25 Apr 2023, 19:31
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://wpscan.com/vulnerability/c8917ba2-4cb3-4b09-8a49-b7c612254946 - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:10web:photo_gallery:*:*:*:*:*:wordpress:*:* | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 4.9  | 
| First Time | 
        
        10web photo Gallery
         10web  | 
17 Apr 2023, 13:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-04-17 13:15
Updated : 2025-02-06 16:15
NVD link : CVE-2023-1427
Mitre link : CVE-2023-1427
CVE.ORG link : CVE-2023-1427
JSON object : View
Products Affected
                10web
- photo_gallery
 
CWE
                No CWE.
