WordPress Cimy User Manager Plugin Arbitrary File Disclosure Vulnerability
1 Nov. 2012
Summary
The Cimy User Manager Plugin for WordPress is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
Input passed via the "cimy_um_filename" parameter to e.g. index.php is not properly sanitised in the "cimy_um_download_database()" function (wp-content/plugins/cimy-user-manager/cimy_user_manager.php) before being used to read files. This can be exploited to disclose the content of arbitrary files via directory traversal sequences.The vulnerability is confirmed in version 1.4.1. Other versions may also be affected.