CVE-2022-1166 Information

Description

The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder as it did not include a default PHP file or .htaccess file. This could expose personal data such as people’s resumes. Although Directory Listing can be prevented by securely configuring the web server vendors can also take measures to make it less likely to happen.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference

https://themeforest.net/item/jobmonster-job-board-wordpress-theme/10965446 https://wpscan.com/vulnerability/ea6646ac-f71f-4340-965d-fab272da5189

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

5.3

Share on: