4.9
CVE-2022-2222
- EPSS 0.84%
- Veröffentlicht 17.07.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:34
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Download Monitor <= 4.5.9 - Authenticated Arbitrary File Download
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Mögliche Gegenmaßnahme
Download Monitor: Update to version 4.5.91, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Download Monitor
Version
* - 4.5.9
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpchill ≫ Download Monitor SwPlatformwordpress Version < 4.5.91
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.84% | 0.738 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.