CVE-2019-1010257
Last modified
CVE-2019-1010257 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. EPSS estimates a 4.36% chance of exploitation in the next 30 days.
Description
An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The file will be deleted after download if the web server has permission to do so. For PHP versions before 5.3, any file can be read by null terminating the string left of the file extension.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Article2pdf Project | Article2pdf | >= 0.24, <= 0.27 |
References
- https://packetstormsecurity.com/files/152236/WordPress-article2pdf-0.24-DoS-File-Deletion-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Mar/49Exploit, Issue Tracking, Mailing List, Third Party Advisory
- https://wordpress.org/support/topic/pdf-download-path-improperly-sanitised/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9246Third Party Advisory
- https://packetstormsecurity.com/files/152236/WordPress-article2pdf-0.24-DoS-File-Deletion-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Mar/49Exploit, Issue Tracking, Mailing List, Third Party Advisory
- https://wordpress.org/support/topic/pdf-download-path-improperly-sanitised/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9246Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1010257?
How severe is CVE-2019-1010257?
How do I fix CVE-2019-1010257?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1010247ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affec…
- CVE-2019-1010248Synetics GmbH I-doit 1.12 and earlier is affected by: SQL In…
- CVE-2019-1010249The Linux Foundation ONOS 2.0.0 and earlier is affected by: …
- CVE-2019-1010250The Linux Foundation ONOS 2.0.0 and earlier is affected by: …
- CVE-2019-1010251Open Information Security Foundation Suricata prior to versi…
- CVE-2019-1010252The Linux Foundation ONOS 2.0.0 and earlier is affected by: …
- CVE-2019-1010258nanosvg library nanosvg after commit c1f6e209c16b18b46aa9f45…
- CVE-2019-1010259SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection.…
- CVE-2019-1010260Using ktlint to download and execute custom rulesets can res…
- CVE-2019-1010261Gitea 1.7.0 and earlier is affected by: Cross Site Scripting…
- CVE-2019-1010262Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-1010263Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Acc…
Are you affected by CVE-2019-1010257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
