Record summary

CVE-2024-10708 has a selected CVSS score of 4.9 (medium); EIP currently links 1 Nuclei template.

Description

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 10, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

System Dashboard

Default status: unaffected

CVE ListBefore 2.8.15affected

Default status: unknown

CVE ListBefore 2.8.15affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSystem Dashboard < 2.8.15 - Admin+ Path TraversalCVSS 4.9

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

Impact

Authenticated administrators can exploit path traversal through the filename parameter in the sd_viewer action to read arbitrary server files including wp-config.php, exposing database credentials and sensitive configuration data.

Remediation

Fixed in 2.8.15

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2024wpscanwordpresswp-pluginlfiauthsystem-dashboardvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:bowo:system_dashboard:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/system-dashboard/"

Source: ProjectDiscovery

References

2