PT-2024-19622 · WordPress · Backuply
Dau Hoang Tai
·
Published
2024-03-15
·
Updated
2024-03-17
·
CVE-2024-2294
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress versions up to, and including, 1.2.7
Description
The issue allows attackers with an account that has only the activate plugins capability to access arbitrary files on the server, potentially containing sensitive information, via a Directory Traversal vulnerability. This is possible through the
backup name parameter in the backuply download backup function. The vulnerability only affects sites hosted on Windows servers.Recommendations
For versions up to, and including, 1.2.7, consider disabling the
backuply download backup function until a patch is available to prevent exploitation.
Restrict access to sensitive files on the server to minimize the risk of information disclosure.
Avoid using the backup name parameter in the affected function until the issue is resolved.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backuply