Duplicator <= 1.2.41 - Sensitive Information Disclosure leading to Remote Code Execution
2018-08-29 00:00
Thomas ChauchefoinStrategic Overview
StatusPatched in 1.2.42
Affected Version
<= 1.2.40CVSS9.8Critical
CVE
CVE-2018-17207Vulnerability Overview
An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
Technical Analysis
REMEDIATION: Update to version 1.2.42, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C