CVE-2024-13671

The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-25155 is likely a duplicate of this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:partitionnumerique:music_sheet_viewer:*:*:*:*:*:wordpress:*:*

History

08 Apr 2026, 18:20

Type Values Removed Values Added
Summary (en) The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. (en) The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-25155 is likely a duplicate of this issue.

31 Jan 2025, 17:50

Type Values Removed Values Added
CPE cpe:2.3:a:partitionnumerique:music_sheet_viewer:*:*:*:*:*:wordpress:*:*
First Time Partitionnumerique
Partitionnumerique music Sheet Viewer
Summary
  • (es) El complemento Music Sheet Viewer para WordPress es vulnerable a la lectura arbitraria de archivos en todas las versiones hasta la 4.1 (y incluida) a través de la función read_score_file(). Esto permite que atacantes no autenticados lean el contenido de archivos arbitrarios en el servidor, que pueden contener información confidencial.
References () https://plugins.trac.wordpress.org/browser/music-sheet-viewer/trunk/music-sheet-viewer.php#L748 - () https://plugins.trac.wordpress.org/browser/music-sheet-viewer/trunk/music-sheet-viewer.php#L748 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/569f1cd4-195b-41d4-85cb-f529a1eb18d4?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/569f1cd4-195b-41d4-85cb-f529a1eb18d4?source=cve - Third Party Advisory
CWE NVD-CWE-noinfo

30 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 14:15

Updated : 2026-04-08 18:20


NVD link : CVE-2024-13671

Mitre link : CVE-2024-13671

CVE.ORG link : CVE-2024-13671


JSON object : View

Products Affected

partitionnumerique

  • music_sheet_viewer
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

NVD-CWE-noinfo