Vulnerabilities > CVE-2023-2117 - Unspecified vulnerability in 10Web Image Optimizer
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |