Vulnerabilities > CVE-2022-0779 - Unspecified vulnerability in User-Meta User Meta User Profile Builder and User Management

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
user-meta

Summary

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads

Vulnerable Configurations

Part Description Count
Application
User-Meta
33