Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1010257

Опубликовано: 27 мар. 2019
Источник: nvd
CVSS3: 9.1
CVSS2: 7.5
EPSS Низкий

Описание

An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The file will be deleted after download if the web server has permission to do so. For PHP versions before 5.3, any file can be read by null terminating the string left of the file extension.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:article2pdf_project:article2pdf:*:*:*:*:*:wordpress:*:*
Версия от 0.24 (включая) до 0.27 (включая)

EPSS

Процентиль: 89%
0.05089
Низкий

9.1 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The file will be deleted after download if the web server has permission to do so. For PHP versions before 5.3, any file can be read by null terminating the string left of the file extension.

EPSS

Процентиль: 89%
0.05089
Низкий

9.1 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22