CVE-2021-24227 Information
Jun 07, 2022
cve
Description
The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector an attacker could leak important internal files like wp-config.php which contains database credentials and cryptographic keys used in the generation of nonces and cookies.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://wpscan.com/vulnerability/f62df02d-7678-440f-84a1-ddbf09364016 https://jetpack.com/2021/03/26/vulnerabilities-found-in-patreon-wordpress-plugin/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: