CVSS Summary
| Score | 4 Medium |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | Single |
| Confidentiality | Partial |
| Integrity | None |
| Availability | None |
Last revised:
The plugin contains a file manager component which allows broad access to the filesystem including deleting files, uploading files, and moving files. In this proof-of-concept we’ll be using path traversal to copy a configuration file from /etc into a web-readable directory in order to allow the attacker to read secrets.
Current state: Fixed
| Score | 4 Medium |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | Single |
| Confidentiality | Partial |
| Integrity | None |
| Availability | None |
The number of ../ you need to add to the URL will vary, and the web server may be configured to only allow reading files with certain extensions.
Upgrade to version 1.3.43 or later.