CVE-2022-1166
JobMonster < 4.6.6.1 - Directory Listing in Upload Folder
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.
El tema JobMonster era vulnerable a un Listado de Directorios en la carpeta /wp-content/uploads/jobmonster/, ya que no incluía un archivo PHP por defecto, ni un archivo .htaccess. Esto podría exponer datos personales como los currículos de las personas. Aunque el Listado de Directorio puede evitarse al configurar de forma segura el servidor web, los proveedores también pueden tomar medidas para que sea menos probable que ocurra
The Noo JobMonster theme is vulnerable to Sensitive Information Disclosure via Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file in versions up to, and including 4.6.6. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-09-11 CVE Published
- 2022-03-30 CVE Reserved
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://themeforest.net/item/jobmonster-job-board-wordpress-theme/10965446 | Product |
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/ea6646ac-f71f-4340-965d-fab272da5189 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nootheme Search vendor "Nootheme" | Jobmonster Search vendor "Nootheme" for product "Jobmonster" | < 4.6.6.1 Search vendor "Nootheme" for product "Jobmonster" and version " < 4.6.6.1" | wordpress |
Affected
|