Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-88xc-3623-x7qh

Опубликовано: 16 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

EPSS

Процентиль: 38%
0.00167
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-538
CWE-552
CWE-668

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

EPSS

Процентиль: 38%
0.00167
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-538
CWE-552
CWE-668