CVE-2024-50497

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:buynowdepot:advanced_online_ordering_and_delivery_platform:*:*:*:*:*:wordpress:*:*

History

31 Oct 2024, 13:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 9.8
Summary
  • (es) La vulnerabilidad de control inadecuado del nombre de archivo para la declaración Include/Require en el programa PHP ('Inclusión de archivo remoto PHP') en BuyNowDepot Advanced Online Ordering and Delivery Platform permite la inclusión de archivos locales PHP. Este problema afecta a la Plataforma avanzada de pedidos y entrega en línea: desde n/a hasta 2.0.0.
References () https://patchstack.com/database/vulnerability/advanced-online-ordering-and-delivery-platform/wordpress-advanced-online-ordering-and-delivery-platform-plugin-2-0-0-local-file-inclusion-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/advanced-online-ordering-and-delivery-platform/wordpress-advanced-online-ordering-and-delivery-platform-plugin-2-0-0-local-file-inclusion-vulnerability?_s_id=cve - Third Party Advisory
CWE CWE-829
First Time Buynowdepot advanced Online Ordering And Delivery Platform
Buynowdepot
CPE cpe:2.3:a:buynowdepot:advanced_online_ordering_and_delivery_platform:*:*:*:*:*:wordpress:*:*

28 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 13:15

Updated : 2024-10-31 13:55


NVD link : CVE-2024-50497

Mitre link : CVE-2024-50497

CVE.ORG link : CVE-2024-50497


JSON object : View

Products Affected

buynowdepot

  • advanced_online_ordering_and_delivery_platform
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')