CVE-2023-7236
Backup Bolt <= 1.3.0 - Sensitive Data Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.
El complemento Backup Bolt de WordPress hasta la versión 1.3.0 es vulnerable a la exposición de la información a través del acceso desprotegido a los registros de depuración. Esto hace posible que atacantes no autenticados recuperen el registro de depuración que puede contener información como errores del sistema que podrían contener información confidencial.
The Backup Bolt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via error log file. This makes it possible for unauthenticated attackers to obtain information about an affected site's configuration, files and directories.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-18 CVE Reserved
- 2024-02-20 CVE Published
- 2024-03-19 EPSS Updated
- 2024-12-04 CVE Updated
- 2024-12-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/2a4557e2-b764-4678-a6d6-af39dd1ba76b | 2024-12-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Backup Bolt Search vendor "Unknown" for product "Backup Bolt" | <= 1.3.0 Search vendor "Unknown" for product "Backup Bolt" and version " <= 1.3.0" | en |
Affected
|