Aspose Importer & Exporter (Discontinued) < 3.0 - Arbitrary File Download
highThe Aspose Importer & Exporter (Discontinued) plugin for WordPress is vulnerable to arbitrary file download in versions up to, and including, 2.0. This is due to lack of sanitization on the 'file' parameter. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server,...
- CVSS:
- 7.5
- Affected:
- up to 2.0
- Fixed in:
- 3.0
- Disclosed:
- Apr 6, 2015