The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
References
Link | Resource |
---|---|
https://drive.google.com/file/d/1w83xWsVLS_gCpQy4LDwbjNK9JaB87EEf/view?usp=sharing | Exploit |
https://wpscan.com/vulnerability/64f2557f-c5e4-4779-9e28-911dfaf2dda5 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-12-18 20:15
Updated : 2023-12-21 19:51
NVD link : CVE-2023-6065
Mitre link : CVE-2023-6065
CVE.ORG link : CVE-2023-6065
JSON object : View
Products Affected
quttera
- quttera_web_malware_scanner
CWE