PT-2024-3160 · Unknown · Backupwordpress
Dk0Pf
+1
·
Published
2024-03-27
·
Updated
2024-04-29
·
CVE-2024-3034
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
BackUpWordPress versions up to, and including, 3.13
Description:
The issue is related to errors in handling relative path to directory when processing the
hmbkp directory browse parameter, allowing remote attackers to gain unauthorized access to protected information. This vulnerability enables authenticated attackers with administrator-level access and above to traverse directories outside of the allowed context via the hmbkp directory browse parameter.Recommendations:
For versions up to, and including, 3.13, consider disabling the
hmbkp directory browse parameter until a patch is available to prevent directory traversal attacks. Restrict access to sensitive directories and ensure that only necessary personnel have administrator-level access to minimize the risk of exploitation.Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Backupwordpress