Описание
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.3 (исключая)
cpe:2.3:a:wpmanageninja:ninja_job_board:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 98%
0.50013
Средний
7.5 High
CVSS3
Дефекты
CWE-425
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.
EPSS
Процентиль: 98%
0.50013
Средний
7.5 High
CVSS3
Дефекты
CWE-425