Lucene search

K
nvd[email protected]NVD:CVE-2023-32623
HistoryJun 28, 2023 - 5:15 a.m.

CVE-2023-32623

2023-06-2805:15:10
CWE-22
web.nvd.nist.gov
1
snow monkey forms
directory traversal
remote attacker
arbitrary files

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

71.8%

Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.

Affected configurations

Nvd
Node
2incsnow_monkey_formsRange<5.1.2wordpress
VendorProductVersionCPE
2incsnow_monkey_forms*cpe:2.3:a:2inc:snow_monkey_forms:*:*:*:*:*:wordpress:*:*

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

71.8%

Related for NVD:CVE-2023-32623