Quttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 19%
exploitation probability
19%top 3% of all CVEs
observed exploitation
nono source reports it
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
Affected products
Unknown · Quttera Web Malware Scanner