CVE-2020-35749: Path Traversal
Directory traversal vulnerability in class-simplejobboardresumedownloadhandler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjbfile parameter to wp-admin/post.php.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this directory traversal vulnerability?
The vulnerability ID for this directory traversal vulnerability is CVE-2020-35749.
What is the affected software?
The affected software is the Simple Board Job plugin version 2.9.3 and earlier for WordPress.
What is the severity of the CVE-2020-35749 vulnerability?
The severity of the CVE-2020-35749 vulnerability is high with a CVSS score of 7.7.
How does this vulnerability work?
This vulnerability allows remote attackers to read arbitrary files by exploiting a directory traversal vulnerability in the class-simple_job_board_resume_download_handler.php file.
Are there any known fixes or patches for this vulnerability?
There may be patches or updates available for the Simple Board Job plugin, so it's recommended to check with the plugin developer or vendor for the latest security updates.