PT-2021-11015 · WordPress · Media File Organizer
Published
2021-07-07
·
Updated
2021-07-10
·
CVE-2020-24144
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Media File Organizer plugin version 1.0.1 for WordPress
Description:
The issue allows an attacker to access files stored outside the web root folder via the
items[] parameter in a move operation. This is a result of a directory traversal vulnerability in the Media File Organizer plugin for WordPress.Recommendations:
For Media File Organizer plugin version 1.0.1, consider disabling the move operation feature until a patch is available to prevent exploitation of the directory traversal vulnerability. Restrict access to sensitive files and folders to minimize the risk of unauthorized access.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Media File Organizer