PT-2024-15099 · Bestwebsoft · Error Log Viewer

Dmitry Ignatyev

·

Published

2024-02-27

·

Updated

2024-08-30

·

CVE-2023-6821

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Error Log Viewer by BestWebSoft WordPress plugin versions prior to 1.1.3
Description The issue allows users to read and download PHP logs without authorization, potentially exposing sensitive data. This is a Directory Listing issue.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Error Log Viewer plugin until a patch is applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6821

Affected Products

Error Log Viewer