cve/2016/CVE-2016-7169.md
2024-06-18 02:51:15 +02:00

911 B

CVE-2016-7169

Description

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

POC

Reference

Github