
🚨*CVE* CVE-2018-25325 Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames thr… https://www.cve.org/CVERecord?id=CVE-2018-25325 ----- Traducción: CVE-2018-25325 Woo… http://infoflow.cloud`
Post summary
The post discloses that WooCommerce CSV Importer version 3.3.6 suffers a path traversal flaw enabling registered users to delete arbitrary files.

