Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7f5-95m3-2fw7

Опубликовано: 06 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

EPSS

Процентиль: 27%
0.00096
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-552

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

EPSS

Процентиль: 27%
0.00096
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-552