WordPress Plugin Vulnerabilities

File Manager < 5.0.2 - Information Disclosure

Description

The Giribaz File Manager plugin logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If user edits wp-config.php file using this plugin, the wp-config.php contents get added to the file which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and an simple dork will find affected sites.

Proof of Concept

Affects Plugins

Fixed in 5.0.2

References

Classification

Type
FPD
CWE
CVSS

Miscellaneous

Submitter
Colette Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2018-03-02 (about 8 years ago)
Added
2018-03-02 (about 8 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other