Lucene search

K
wpexploitViktor MarkopoulosWPEX-ID:51B4752A-7922-444D-A022-F1C7159B5D84
HistoryJun 28, 2022 - 12:00 a.m.

SP Project & Document Manager < 4.58 - Sensitive File Disclosure

2022-06-2800:00:00
Viktor Markopoulos
78
sensitive data
file disclosure
vulnerable site
upload plugin

EPSS

0.001

Percentile

32.8%

The plugin uses an easily guessable path to store user files, bad actors could use that to access other users’ sensitive files.

1. Upload a file using the plugin.
2. On another browser, access the newly uploaded file via:

https://vulnerable-site.tld/wp-content/uploads/sp-client-document-manager/[user's uid]/file.format

EPSS

0.001

Percentile

32.8%

Related for WPEX-ID:51B4752A-7922-444D-A022-F1C7159B5D84