Vulnerabilities > CVE-2021-39327 - Incomplete Cleanup vulnerability in Ait-Pro Bulletproof Security

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ait-pro
CWE-459

Summary

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

Vulnerable Configurations

Part Description Count
Application
Ait-Pro
132

Common Weakness Enumeration (CWE)