CVE-2024-49249
Published: 07 January 2025
Description
Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.This issue affects SMSA Shipping: from n/a through <= 2.3.
Security Summary
CVE-2024-49249 is a path traversal vulnerability in the SMSA Express SMSA Shipping Official WordPress plugin (smsa-shipping-official), affecting all versions up to and including 2.3. The issue, triggered by the '.../...//' traversal pattern, enables unauthorized file access and is rated with a CVSS v3.1 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), mapped to CWE-35.
Remote unauthenticated attackers can exploit this vulnerability over the network with low attack complexity and no user interaction required. Exploitation allows arbitrary file deletion on the affected WordPress server, leading to significant availability impacts across the scoped components due to the changed scope (S:C).
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/smsa-shipping-official/vulnerability/wordpress-smsa-shipping-plugin-2-3-arbitrary-file-deletion-vulnerability?_s_id=cve characterizes this as an arbitrary file deletion vulnerability in SMSA Shipping plugin versions up to 2.3, providing details for security practitioners to assess and address the risk.
Details
- CWE(s)