← Back

Amministrazione Aperta

amministrazione_aperta

Vendor: Amministrazione Aperta Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amministrazione Aperta Project
1Amministrazione Aperta
Jun 17, 2026
May 16, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenti...Show more
The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious linkShow less