First published: Wed Sep 19 2018(Updated: )
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Snapcreek Duplicator | <1.2.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-17207 is critical with a severity value of 9.8.
CVE-2018-17207 allows an attacker to inject PHP code into wp-config.php during the database setup step, leading to arbitrary code execution.
An attacker can exploit CVE-2018-17207 by accessing leftover installer files (installer.php and installer-backup.php) and injecting PHP code during the database setup step.
Yes, the fix for CVE-2018-17207 is available in Snap Creek Duplicator version 1.2.42.
You can find more information about CVE-2018-17207 in the Snap Creek Duplicator documentation and the Synacktiv advisory.