vendor:
aspose-doc-exporter Plugin
by:
Ashiyane Digital Security Team
7.5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: aspose-doc-exporter Plugin
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, Linux
2015
WordPress aspose-doc-exporter Plugin Arbitrary File Download Vulnerability
The vulnerability allows an attacker to download arbitrary files from the target system by exploiting a flaw in the aspose-doc-exporter plugin for Wordpress. By manipulating the 'file' parameter in the vulnerable PHP script, an attacker can traverse directories and download sensitive files.
Mitigation:
Remove or update the vulnerable plugin. Restrict access to the vulnerable file or sanitize user input to prevent directory traversal attacks.