Lucene search

K
wpvulndbDaniel RufWPVDB-ID:A9BCC68C-EEDA-4647-8463-E7E136733053
HistoryAug 01, 2022 - 12:00 a.m.

Ninja Job Board < 1.3.3 - Resume Disclosure via Directory Listing

2022-08-0100:00:00
Daniel Ruf
wpscan.com
18
ninja job board
resume disclosure
directory listing
vulnerability
unauthenticated access
data breach

EPSS

0.011

Percentile

84.5%

The plugin does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

PoC

curl https://example.com/wp-content/uploads/wpjobboard Search for this path / folder in search engines to find uploaded resumes.

EPSS

0.011

Percentile

84.5%

Related for WPVDB-ID:A9BCC68C-EEDA-4647-8463-E7E136733053