What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusion.This issue affects MegaMenu: from n/a through 2.3.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusion.This issue affects MegaMenu: from n/a through 2.3.12.
Explanation of Vulnerability in Simple Terms
MegaMenu versions up to 2.3.12 contain a path traversal vulnerability that allows an attacker to read arbitrary files from the server. The vulnerability requires specific conditions to exploit but can result in exposure of sensitive configuration files, database credentials, and other protected data. Sites running affected versions should update immediately.
What an attacker can do
Read arbitrary files from the server, including configuration files and credentials.
Potential impact on your site
Sensitive files like wp-config.php or database credentials could be exposed to attackers.
Conditions required to exploit
Network access; specific attack complexity conditions must be met.
Key dates
External resources
Related vulnerabilities