CVE-2018-7204

Bit File Manager <= 5.0.0 - Information Disclosure

highInsertion of Sensitive Information into Log File
7.5
CVSS Score
7.5
CVSS Score
high
Severity
5.0.2
Patched in
2153d
Time to patch

Description

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
High
Confidentiality
None
Integrity
None
Availability

Technical Details

Affected versions<=5.0.0
PublishedMarch 2, 2018
Last updatedJanuary 22, 2024
Affected pluginfile-manager

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.