From dfc4a64fdcb13fc41e790c52aa63b9c88df4c16d Mon Sep 17 00:00:00 2001 From: GitHub Action Date: Sun, 17 Oct 2021 11:26:16 +0000 Subject: [PATCH] Auto Generated CVE annotations [Sun Oct 17 11:26:16 UTC 2021] :robot: --- cves/2015/CVE-2015-4694.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/cves/2015/CVE-2015-4694.yaml b/cves/2015/CVE-2015-4694.yaml index c273f16a80..97b8256f1d 100644 --- a/cves/2015/CVE-2015-4694.yaml +++ b/cves/2015/CVE-2015-4694.yaml @@ -7,6 +7,11 @@ info: description: The zip-attachments plugin allows arbitrary file downloads because it does not check the download path of the requested file. reference: https://wpscan.com/vulnerability/8047 tags: lfi,wordpress,cve,cve2015,wp-plugin + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N + cvss-score: 8.60 + cve-id: CVE-2015-4694 + cwe-id: CWE-22 requests: - method: GET