HTML5 MP3 Player with Playlist <= 2.7.0 - Full Path Disclosure
2014-11-26 00:00
KnocKoutStrategic Overview
StatusPatched in 2.8.0
Affected PluginHTML5 MP3 Player with Playlist Free
Affected Version
<= 2.7.0CVSS5.3Medium
CVE
CVE-2014-9177Vulnerability Overview
The HTML5 MP3 Player with Playlist Free plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to reveal sensitive full path information via sending a request to html5plus/playlist.php.
Technical Analysis
REMEDIATION: Update to version 2.8.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C