Duplicator <= 1.2.41 - Sensitive Information Disclosure leading to Remote Code Execution

2018-08-29 00:00
Thomas Chauchefoin

Vulnerability Overview

An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

Technical Analysis

REMEDIATION: Update to version 1.2.42, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C