cleantalk
Vulnerabilities and Security Researches

SupportCandy – Helpdesk & Customer Support Ticket System, 8006425dda55057d21f8b0f0632777b5b3962977

Published on
Mar 28, 2023
Research Description
SupportCandy &#8211; Helpdesk &amp; Customer Support Ticket System [supportcandy] < 3.1.4 SupportCandy <= 3.1.3 - Sensitive Data Exposure The SupportCandy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.1.3. Users seeking support have the option to upload supporting documents which are placed in /wp-content/uploads/wpsc/. If directory listing is enabled, an attacker can obtain a listing of documents in this directory and access documents directly.
Affected versions
max 3.1.4.
Status
vulnerable