← voltar
CVE-2022-1166

JobMonster < 4.6.6.1 - Directory Listing in Upload Folder

EPSS 1.5%CWE-22
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS EPSS 1.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 abr 2022Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.
Produtos afetados
Unknown · Noo JobMonster

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →