CVE-2022-4748 is a critical path traversal vulnerability affecting FlatPress, specifically within the doItemActions function of the fp-plugins/mediamanager/panels/panel.mediamanager.file.php file. This flaw allows an unauthenticated attacker to manipulate the 'deletefile' argument to traverse directories, potentially leading to arbitrary file deletion or other system compromise. With a CVSS score of 9.8, it presents a high risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploits, or significant community discussion have been observed, a patch (5d5c7f6d8f072d14926fc2c3a97cdd763802f170) is available and recommended for immediate application.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:flatpress:flatpress:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.