The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
References
Link | Resource |
---|---|
https://wpvulndb.com/vulnerabilities/8167 | Exploit Third Party Advisory VDB Entry |
https://vagmour.eu/cve-2015-6668-cv-filename-disclosure-on-job-manager-wordpress-plugin/ | Exploit Technical Description Third Party Advisory |
Configurations
Information
Published : 2017-10-19 14:29
Updated : 2017-11-07 05:05
NVD link : CVE-2015-6668
Mitre link : CVE-2015-6668
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
wp-jobmanager
- job_manager