Path traversal in SnapCreek Duplicator - CVE-2020-11738
Published: April 14, 2020 / Updated: June 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to insufficient sanitization of user-supplied passed via . A remote attacker can send a specially crafted HTTP request containing directory traversal sequences and read contents of arbitrary files on the system.
Affected software
How to mitigate CVE-2020-11738
Links to Public Exploits and PoC-codes
- Exploit #10077 - wordpress-snapcreek (snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/) (June 21, 2024)
- Exploit #7049 - Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (November 25, 2021)
- Exploit #4953 - WordPress Duplicator File Read Vulnerability (December 19, 2020)