Cimy User Manager < 1.4.4 - Arbitrary File Read
highThe Cimy User Manager plugin for WordPress is vulnerable to Directory Traversal in versions before 1.4.4 via the 'cimy_um_filename' parameter. This allows attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Oct 24, 2012