CVE-2023-5355 PUBLISHED CVSS 8.100000381469727 HIGH

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

EPSS 0.17% · 37.6th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.17%
37.6th percentile

Affected Products

VendorProductVersions
getawesomesupportawesome_support0, 0, 0
UnknownAwesome Support0, 0, 0

Timeline

References

Open in Interactive Console →