Noo JobMonster <= 4.6.6 - Sensitive Information Disclosure via Directory Listing

2020-09-11 00:00
Daniel Ruf

Strategic Overview

Status
Patched in 4.6.6.1
Affected ThemeNoo JobMonster
Affected Version<= 4.6.6
CVSS5.3Medium
CVECVE-2022-1166
View all Noo JobMonster vulnerabilities

Vulnerability Overview

The Noo JobMonster theme is vulnerable to Sensitive Information Disclosure via Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file in versions up to, and including 4.6.6. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.

Technical Analysis

REMEDIATION: Update to version 4.6.6.1, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C