BetterDocs Path Traversal Vulnerability Affects PHP Local File Inclusion
CVE-2024-43129
8.8HIGH
Summary
A vulnerability exists in WPDeveloper BetterDocs that entails improper limitations on pathname access to a restricted directory, allowing for Path Traversal. This lapse permits attackers to manipulate file paths, facilitating PHP Local File Inclusion, which can result in unauthorized access to sensitive files on the server. The affected version range includes BetterDocs from its initial release up to version 3.5.8, necessitating immediate action for users to remediate the potential security exposure.
Affected Version(s)
BetterDocs <= 3.5.8
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)