What the vulnerability does
01Description
Contributor Local File Inclusion in Vino <= 1.9 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Contributor Local File Inclusion in Vino <= 1.9 versions.
Explanation of Vulnerability in Simple Terms
Vino version 1.9 and earlier contains a vulnerability that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The attack requires network access and high technical complexity. Administrators should update to a version newer than 1.9 as soon as possible.
What an attacker can do
Read sensitive data, modify site content, or disrupt service availability.
Potential impact on your site
Authenticated users can access confidential information, alter pages/posts, or cause downtime.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities