The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in all versions up to, and including, 1.1.5 via the 'bookingpress_save_lite_wizard_settings_func' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files that contain the content of files (either on the local server or from a remote location), allowing the execution of any PHP code in those files or the exposure of sensitive information.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HReputeinfosystems Bookingpress
APPReputeinfosystems< 1.1.6
Powiązane podatności
SQL Injection w pluginie BookingPress dla WordPress (bez uwierzytelnienia)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputein...
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vu...
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Pr...
The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename val...