The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
References
Link | Resource |
---|---|
https://vagmour.eu/cve-2015-6668-cv-filename-disclosure-on-job-manager-wordpress-plugin/ | Exploit Technical Description Third Party Advisory |
https://wpvulndb.com/vulnerabilities/8167 | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2017-10-19 21:29
Updated : 2024-02-04 19:29
NVD link : CVE-2015-6668
Mitre link : CVE-2015-6668
CVE.ORG link : CVE-2015-6668
JSON object : View
Products Affected
wp-jobmanager
- job_manager
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor