CVE-2014-8605
Last modified
CVE-2014-8605 is a vulnerability of currently unknown severity. The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.. EPSS estimates a 7.12% chance of exploitation in the next 30 days.
Description
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xcloner | Xcloner | 3.1.1 |
| Xcloner | Xcloner | 3.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-8605?
How severe is CVE-2014-8605?
How do I fix CVE-2014-8605?
Are you affected by CVE-2014-8605?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
