1 results (0.003 seconds)

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

11 Jul 2024 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories) allows Path Traversal, Server Side Request Forgery.This issue affects MakeStories (for Google Web Stories): from n/a through 3.0.3. The MakeStories (for Google Web Stories) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ms_image_proxy() function in all versions up to, and including, 3.0.3. This makes ... • https://patchstack.com/database/vulnerability/makestories-helper/wordpress-makestories-for-google-web-stories-plugin-3-0-3-arbitrary-file-download-and-ssrf-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-862: Missing Authorization •