CVE-2018-7204

HIGH

Giribaz File Manager < 5.0.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_confirm
https://wordpress.org/plugins/file-manager/#developers
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9036
Patch, Third Party Advisory x_refsource_confirm
https://plugins.trac.wordpress.org/changeset/1823035/file-manager

Scores

CVSS v3 7.5
EPSS 0.0075
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
giribaz/file_manager < 5.0.0
Published Mar 07, 2018
Tracked Since Feb 18, 2026