SupportCandy – Helpdesk & Customer Support Ticket System, 8006425dda55057d21f8b0f0632777b5b3962977
- CVE, Research URL
- Home page URL
-
Security reports for SupportCandy – Helpdesk & Customer Support Ticket System
- Published on
- Mar 28, 2023
- Research Description
- SupportCandy – Helpdesk & Customer Support Ticket System [supportcandy] < 3.1.4 SupportCandy <= 3.1.3 - Sensitive Data Exposure The SupportCandy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.1.3. Users seeking support have the option to upload supporting documents which are placed in /wp-content/uploads/wpsc/. If directory listing is enabled, an attacker can obtain a listing of documents in this directory and access documents directly.
- Affected versions
-
max 3.1.4.
- Status
-
vulnerable