Vulnerabilities
Vulnerable Software
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through 4.15.
CVSS Score
8.1
EPSS Score
0.005
Published
2025-01-07
The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file
CVSS Score
6.1
EPSS Score
0.001
Published
2022-08-22


Contact Us

Shodan ® - All rights reserved