PT-2020-19491 · WordPress · Wp Database Backup
Published
2020-01-20
·
Updated
2022-04-18
·
CVE-2020-7241
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Database Backup plugin through 5.5 for WordPress
Description
The issue allows attackers to potentially read ZIP archives by guessing random ID numbers, date strings in a specific format, or UNIX timestamps, and then making HTTPS requests with the complete guessed URL to the default local storage directory wp-content/uploads/db-backup/.
Recommendations
For WP Database Backup plugin through 5.5, consider changing the default download storage directory to a more secure location or implementing measures to prevent unauthorized access to the wp-content/uploads/db-backup/ directory until a patch is available.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Database Backup