What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This issue affects Newspack Blocks: from n/a through 3.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This issue affects Newspack Blocks: from n/a through 3.0.8.
Explanation of Vulnerability in Simple Terms
Newspack Blocks versions up to 3.0.8 contain a path traversal vulnerability that allows authenticated users with low privileges to manipulate file paths and cause the site to become unavailable. The vulnerability affects the scope beyond the vulnerable component itself. No confidentiality impact occurs, but integrity and availability are compromised.
What an attacker can do
Make the site unavailable or modify files by exploiting a path traversal flaw.
Potential impact on your site
Site downtime or file modification by authenticated users with minimal permissions.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities