Vulnerabilities > CVE-2023-2288 - Deserialization of Untrusted Data vulnerability in Themeisle Otter
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |