Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2v4-55f4-q786

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

EPSS

Процентиль: 94%
0.1532
Средний

5.3 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.3
nvd
почти 8 лет назад

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

EPSS

Процентиль: 94%
0.1532
Средний

5.3 Medium

CVSS3

Дефекты

CWE-532