← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-7204

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:2.87%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
giribaz file_manager all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.872%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-02-17T00:00:00
Published2018-03-07T20:00:00
Patch Date2018-03-02
Last Updated2024-08-05T06:24:11

LINK COPIED TO CLIPBOARD