CVE Feed

    Dashboard / CVE / CVE-2022-1560

    CVE-2022-1560

    The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link

    Published:May 16, 2022
    Last Modified:Nov 21, 2024
    EPS:May 16, 2022
    EPSS Score:0.35147
    CVSS Score:6.5

    Affected Products

    Vendor
    Amministrazione Aperta Project
    Product
    Amministrazione Aperta

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High