// For flags

CVE-2022-0493

String Locator < 2.5.0 - Admin+ Arbitrary File Read

Severity Score

4.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

El plugin String locator de WordPress versiones anteriores a 2.5.0, no comprueba correctamente la ruta de los archivos a buscar, permitiendo a usuarios con altos privilegios como el admin consultar archivos arbitrarios en el servidor web por medio de un vector de salto de ruta. Además, debido a un fallo en la búsqueda, que permite proporcionar un patrón, que será usado para dar salida a las coincidencias relevantes del archivo coincidente, todo el contenido del archivo puede ser divulgado

*Credits: qerogram
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-04 CVE Reserved
  • 2022-03-01 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
String Locator Project
Search vendor "String Locator Project"
String Locator
Search vendor "String Locator Project" for product "String Locator"
< 2.5.0
Search vendor "String Locator Project" for product "String Locator" and version " < 2.5.0"
wordpress
Affected