CVE-2019-1010257
Summary
| CVE | CVE-2019-1010257 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-27 19:30:00 UTC |
| Updated | 2023-02-28 20:46:00 UTC |
| Description | An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The file will be deleted after download if the web server has permission to do so. For PHP versions before 5.3, any file can be read by null terminating the string left of the file extension. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Article2pdf Project | Article2pdf | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress article2pdf 0.24 DoS / File Deletion / Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| article2pdf - Multiple Vulnerabilities | MISC | wpvulndb.com | |
| PDF download path improperly sanitised | WordPress.org | MISC | wordpress.org | Third Party Advisory |
| Bugtraq: [article2pdf (Wordpress plug-in)] Multiple vulnerabilities (CVE-2019-1000031, CVE-2019-1010257) | BUGTRAQ | seclists.org | Exploit, Issue Tracking, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.