vendor:
ELISQLREPORTS
by:
Felipe Molina
7.5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: ELISQLREPORTS
Affected Version From: < 4.11.33
Affected Version To: 4.11.37
Patch Exists: YES
Related CWE:
CPE: a:wordpress:elisqlreports
Platforms Tested: Debian GNU/Linux 7 with Wordpress 4.3
2015
EZ SQL Reports < 4.11.37: Arbitrary File Download (admin/colaborator required)
The plugin allows a wordpress site administrator or collaborator to download arbitrary files from the host file system though the plugin functionality of downloading .sql, .sql.zip or .sql.gz files created by the wordpress administrator. The file name to download is not sanitized and path traversal can be injected in the request.
Mitigation:
Upgrade to version 4.11.37