Path Traversal Vulnerability Affects Jobmonster
CVE-2024-37928

8.6HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
12 July 2024

Summary

The vulnerability present in NooTheme's Jobmonster product is characterized by improper limitation of a pathname, which allows for path traversal. This flaw permits unauthorized file manipulation, enabling attackers to navigate through the directory structure beyond the intended boundaries. As a result, attackers can potentially delete or alter sensitive files, leading to severe consequences for system integrity and data security. The affected versions include those from the initial release up to 4.7.0. Addressing this vulnerability is essential to ensure the security of user data and the stable operation of the Jobmonster theme.

Affected Version(s)

Jobmonster <= 4.7.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.