← back
CVE-2022-1166

JobMonster < 4.6.6.1 - Directory Listing in Upload Folder

EPSS 1.5%CWE-22
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
04 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.
Affected products
Unknown · Noo JobMonster

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →