cleantalk
Vulnerabilities and Security Researches

BP Group Documents, 017039dd2ef18af36cf0536621a9371c7af772c9

Application

BP Group Documents

Published on
Oct 04, 2013
Research Description
BP Group Documents [bp-group-documents] < 1.2.2 BP Group Documents <= 1.2.1 - Path Traversal The Group Documents plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.2.1 via the bp-group-documents-settings.php file. This allows unauthenticated attackers to change the location of any file the compromised user has access to in the upload directories.
Affected versions
max 1.2.2.
Status
vulnerable