Description
Acunetix uploaded a ZIP file containing a symlink to /etc/passwd. It looks like that web application processed this file and returned the contents of /etc/passwd in response.
Remediation
The web application should filter symlinks included inside ZIP files.
References
Related Vulnerabilities
WordPress Plugin Modern Events Calendar Lite Multiple Vulnerabilities (5.16.2)
WordPress Plugin Stop User Enumeration User Enumeration (1.2.4)
WordPress Plugin MM Forms Community 'doajaxfileupload.php' Arbitrary File Upload (2.2.6)
WordPress Plugin WP REST API (WP API) Information Disclosure (1.2)
WordPress Plugin Simple Dropbox Upload Arbitrary File Upload (1.8.8)