Themes Vulnerabilities

JobMonster < 4.6.6.1 - Directory Listing in Upload Folder

Description

The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.

Proof of Concept

https://example.com/wp-content/uploads/jobmonster

Affects Themes

Fixed in 4.6.6.1

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Daniel Ruf
Submitter
Daniel Ruf
Submitter website
Verified
No

Timeline

Publicly Published
2020-09-21 (about 3 years ago)
Added
2020-09-21 (about 3 years ago)
Last Updated
2022-04-08 (about 2 years ago)

Other