WordPress Plugin amministrazione-aperta
cpe:2.3:a:amministrazione_aperta_project:amministrazione_aperta:*:*:*:*:wordpress:*:*
- <= 3.7.3
A local file read vulnerability has been identified in the WordPress Plugin Amministrazione Aperta, version 3.7.3. This vulnerability allows unauthenticated attackers to read arbitrary files by exploiting inadequate input validation in the 'open' GET parameter of 'dispatcher.php'. Attackers can manipulate the 'open' parameter to include and access sensitive files that are accessible to the web server.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.
To reproduce this vulnerability, send a GET request to 'dispatcher.php' within the 'wpgov' directory of the 'amministrazione-aperta' plugin. Include the 'open' parameter with a file path that points to a sensitive file accessible by the web server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.