RSS   Vulnerabilities for 'Newsletter'   RSS

2019-08-15
 
CVE-2019-14788

CWE-22
 

 
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.

 

 >>> Vendor: Tribulant 5 Products
Newsletter
Tibulant slideshow gallery
Slideshow gallery
Newsletters
One click ssl


Copyright 2024, cxsecurity.com

 

Back to Top