CVE-2023-7165
JetBackup < 2.0.9.9 - Directory Listing Exposing Backups
Record summary
CVE-2023-7165 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
JetBackupDefault status: unaffected | CVE List | Before 2.0.9.9 | affected |
jetbackupBrowse jetbackup / jetbackupDefault status: unknown | CVE List | Before 2.0.9.9 | affected |
Nuclei templates
1ProjectDiscoveryHIGHJetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory ListingCVSS 7.5
JetBackup WordPress plugin <= 2.0.9.9 does not use index files to prevent directory listing in certain configurations, letting malicious actors leak backup files, exploit requires access to the web server.
Impact
Attackers can access and leak sensitive backup files, potentially leading to data exposure and security breaches.
Remediation
Update to version 2.0.9.9 or later that implements index files to prevent directory listing.
Source: ProjectDiscovery