cleantalk
Vulnerabilities and Security Researches

Aspose.PDF Exporter, 4e4634889e32cede4d449b4f63537ec92e40df54

Application

Aspose.PDF Exporter

Published on
Mar 29, 2015
Research Description
Aspose.PDF Exporter [aspose-pdf-exporter] < 2.0 (closed) Aspose.PDF Exporter < 2.0 - Arbitrary File Download The Aspose.PDF Exporter plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.0. This is due to insufficient input sanitization of the 'file' parameter. This makes it possible for unauthenticated attackers to download any file, including configuration files.
Affected versions
max 2.0.
Status
vulnerable