Podatność CVE-2021-39327


Publikacja: 2021-09-17

Opis:
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
Med.
WordPress BulletProof Security 5.1 Information Disclosure
Ron Jost
06.10.2021

Typ:

CWE-200

(Information Exposure)

 Referencje:
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39327
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2591118%40bulletproof-security&new=2591118%40bulletproof-security&sfp_email=&sfph_mail
=

Copyright 2024, cxsecurity.com

 

Back to Top