← Back to browse · API

CVE-2023-2288

Severity
HIGH
CVSS
8.8
EPSS
0.17973
Risk score
41.49
CISA KEV
No
PoC
No
Published
2023-05-30
Modified
2025-01-10
First seen
2026-08-07
Aliases
EUVD-2023-33794, GHSA-7484-6482-4GQ2
Products
Unknown:Otter 0 <2.2.6
Sources
euvd EUVD-2023-33794

Description

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

References