Описание
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.9.9 (исключая)
cpe:2.3:a:jetbackup:jetbackup:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 70%
0.00649
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
github
почти 2 года назад
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
EPSS
Процентиль: 70%
0.00649
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo