7.5

CVE-2024-5599

FileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory Listing

FileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory Listing

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 via the 'fileorganizer_ajax_handler' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.
Mögliche Gegenmaßnahme
FileOrganizer – WordPress File Manager: Update to version 1.0.8, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FileorganizerFileorganizer SwPlatformwordpress Version < 1.0.8
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt FileOrganizer – WordPress File Manager
Version *-1.0.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.401
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-922 Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

https://plugins.trac.wordpress.org/browser/fileorganizer/trunk/main/ajax.php#L85
Product
https://plugins.trac.wordpress.org/changeset/3098763/
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/78e7b65d-91f8-477e-b992-3148c1b65d7b?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/78e7b65d-91f8-477e-b992-3148c1b65d7b
Third Party Advisory