Record summary

CVE-2015-1000005 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Candidate Application Form <= 1.3 - Local File InclusionCVSS 7.5

WordPress Candidate Application Form <= 1.3 is susceptible to arbitrary file downloads because the code in downloadpdffile.php does not do any sanity checks.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server.

Remediation

Update to the latest version of the plugin.

WeaknessesCWE-22
AuthorsdhiyaneshDK
Template tagscve2015cvewpscanwordpresswp-pluginlfiwpcandidate-application-form_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:candidate-application-form_project:candidate-application-form:1.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3