PT-2024-15758 · WordPress · Backuply

Bence Szalai

·

Published

2024-01-26

·

Updated

2024-02-01

·

CVE-2024-0697

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Backuply – Backup, Restore, Migrate and Clone plugin for WordPress versions up to, and including, 1.2.3
Description The issue allows attackers with administrator privileges or higher to read the contents of arbitrary files on the server, which can contain sensitive information, via the node id parameter in the backuply get jstree function. This is a Directory Traversal vulnerability.
Recommendations For versions up to, and including, 1.2.3, consider disabling the backuply get jstree function until a patch is available to prevent exploitation. Restrict access to the node id parameter to minimize the risk of arbitrary file reading.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-0697

Affected Products

Backuply