What the vulnerability does
01Description
Relative Path Traversal vulnerability in Shah Alom Delete Comments By Status delete-comments-by-status allows Path Traversal.This issue affects Delete Comments By Status: from n/a through <= 2.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Relative Path Traversal vulnerability in Shah Alom Delete Comments By Status delete-comments-by-status allows Path Traversal.This issue affects Delete Comments By Status: from n/a through <= 2.1.1.
Explanation of Vulnerability in Simple Terms
Delete Comments By Status versions 2.1.1 and earlier contain a vulnerability that allows an attacker to read sensitive data, modify site content, or disrupt service. The attack requires network access and user interaction (such as clicking a malicious link). The vulnerability stems from improper input validation. Site administrators should update to a version newer than 2.1.1 as soon as a patch is available.
What an attacker can do
Read sensitive data, modify site content, or disrupt service availability.
Potential impact on your site
Unauthorized access to sensitive information, content tampering, or temporary service disruption.
Conditions required to exploit
Attacker must trick a user into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities