Vulnerabilities > CVE-2023-0331 - Unspecified vulnerability in Correos Oficial
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |