A vulnerability has been discovered in Worker Filemanager 2.7. The problem lies in the temporary permissions set on a destination directory during data transfer. As a result, during a specific time window an attacker may be capable of accessing sensitive files located in the directory. Exploitation of this issue may allow an attacker to view sensitive data located in files within the directory. Though unconfirmed, it may also be possible to tamper with these files if they are writeable in such a way that elevated privileges may be obtained.
A vulnerability has been discovered in Worker Filemanager 2.7. The problem lies in the temporary permissions set on a destination directory during data transfer. As a result, during a specific time window an attacker may be capable of accessing sensitive files located in the directory. Exploitation of this issue may allow an attacker to view sensitive data located in files within the directory. Though unconfirmed, it may also be possible to tamper with these files if they are writeable in such a way that elevated privileges may be obtained.