ID:8510 - Exploit for Improper Authorization in BackupBuddy - CVE-2022-31474
Published: October 21, 2022
BackupBuddy
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to download arbitrary files from the server.
The vulnerability exists due to missing authorization for the feature responsible for remote downloading remote backups. A remote non-authenticated attacker can download arbitrary files from the server.
Note, the vulnerability is being actively exploited in the wild.