Simple File List Plugin <= 3.2.4 - Unauthenticated Arbitrary File Download



Description
This vulnerability allows any user can download sensitive information by traversing the path
Authentication required: NO
Affected version: 3.2.4 or below
Fixed version:3.2.5

Affects Plugin

fixed in version 3.2.5

References

URL https://docs.google.com/document/d/1qIZXTzEpI4tO6832vk1KfsSAroT0FY2l--THlhJ8z3c/edit?usp=sharing
URL https://plugins.trac.wordpress.org/changeset/2093272/simple-file-list

Classification

Type TRAVERSAL
CWE CWE-22

Miscellaneous

Original Researcher Admavidhya N
Submitter Admavidhya N
Views 2101
Verified No
WPVDB ID 9287

Timeline

Publicly Published 2019-05-23 (28 days ago)
Added 2019-05-27 (23 days ago)
Last Updated 2019-05-27 (23 days ago)

Copyright & License

Copyright All data and resources contained within this page and this web site is Copyright © The WPScan Team.
License Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us.