CVSS Summary
Score | 4 Medium |
---|---|
Vector | Network |
Complexity | Low |
Authentication | Single |
Confidentiality | Partial |
Integrity | None |
Availability | None |
Last revised:
The plugin contains a file manager component which allows broad access to the filesystem including deleting files, uploading files, and moving files. In this proof-of-concept we’ll be using path traversal to copy a configuration file from /etc into a web-readable directory in order to allow the attacker to read secrets.
Current state: Fixed
Score | 4 Medium |
---|---|
Vector | Network |
Complexity | Low |
Authentication | Single |
Confidentiality | Partial |
Integrity | None |
Availability | None |
The number of ../ you need to add to the URL will vary, and the web server may be configured to only allow reading files with certain extensions.
Upgrade to version 1.3.43 or later.