CVE-2022-1166: JobMonster < 4.6.6.1 - Directory Listing in Upload Folder
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1166?
CVE-2022-1166 has a moderate severity level due to potential exposure of personal data.
How do I fix CVE-2022-1166?
To fix CVE-2022-1166, add a default PHP file or .htaccess file to the /wp-content/uploads/jobmonster/ directory.
What type of vulnerability is CVE-2022-1166?
CVE-2022-1166 is a Directory Listing vulnerability that can expose sensitive files.
Which versions of JobMonster are affected by CVE-2022-1166?
CVE-2022-1166 affects JobMonster versions up to but not including 4.6.6.1.
What data could be exposed due to CVE-2022-1166?
CVE-2022-1166 could expose personal data, including users' resumes.