CVSS Summary
| Score | 4 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Low | 
| Authentication | Single | 
| Confidentiality | Partial | 
| Integrity | None | 
| Availability | None | 
Last revised:
The plugin contains a file manager component which allows broad access to the filesystem including deleting files, uploading files, and moving files. In this proof-of-concept we’ll be using path traversal to copy a configuration file from /etc into a web-readable directory in order to allow the attacker to read secrets.
Current state: Fixed
| Score | 4 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Low | 
| Authentication | Single | 
| Confidentiality | Partial | 
| Integrity | None | 
| Availability | None | 
The number of ../ you need to add to the URL will vary, and the web server may be configured to only allow reading files with certain extensions.
Upgrade to version 1.3.43 or later.