cve/2023/CVE-2023-6065.md
2024-06-18 02:51:15 +02:00

19 lines
845 B
Markdown

### [CVE-2023-6065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6065)
![](https://img.shields.io/static/v1?label=Product&message=Quttera%20Web%20Malware%20Scanner&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%203.4.2.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%20Information%20Exposure&color=brighgreen)
### Description
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
### POC
#### Reference
- https://drive.google.com/file/d/1w83xWsVLS_gCpQy4LDwbjNK9JaB87EEf/view?usp=sharing
- https://wpscan.com/vulnerability/64f2557f-c5e4-4779-9e28-911dfaf2dda5
#### Github
No PoCs found on GitHub currently.