Aller au contenu

Fiche vulnérabilité

CVE-2023-5991 : faille critique motopress hotel booking lite (CVSS 9.8)

Description

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 déc. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • motopress hotel booking lite

Références

Rechercher une autre vulnérabilité dans la base CVE