WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-10 13:16
Updated : 2026-07-24 19:10
NVD link : CVE-2022-50956
Mitre link : CVE-2022-50956
CVE.ORG link : CVE-2022-50956
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
