CVE-2024-13911
CVE-2024-13911
Título es
CVE-2024-13911
Sáb, 01/03/2025 – 08:15
Tipo
CWE-200
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-13911
Descripción en
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to extract sensitive data including full database credentials.
01/03/2025
01/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
7.20
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
https://plugins.trac.wordpress.org/browser/database-backup/trunk/dashboard/backup.php#L62
https://plugins.trac.wordpress.org/browser/database-backup/trunk/dashboard/backup.php#L63
https://plugins.trac.wordpress.org/browser/database-backup/trunk/dashboard/backup.php#L64
https://plugins.trac.wordpress.org/browser/database-backup/trunk/dashboard/backup.php#L65
https://plugins.trac.wordpress.org/browser/database-backup/trunk/dashboard/backup.php#L66
https://plugins.trac.wordpress.org/changeset/3247917/
https://www.wordfence.com/threat-intel/vulnerabilities/id/c548b70a-8566-4aaf-a3a2-fce6c19e6a0c?source=cve
Enviar en el boletín
Off