4.9
CVE-2022-2222
- EPSS 0.93%
- Veröffentlicht 17.07.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:34
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Download Monitor < 4.5.91 - Admin+ Arbitrary File Download
Download Monitor <= 4.5.9 - Authenticated Arbitrary File Download
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Mögliche Gegenmaßnahme
Download Monitor: Update to version 4.5.91, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpchill ≫ Download Monitor SwPlatformwordpress Version < 4.5.91
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Download Monitor
Version
*-4.5.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.93% | 0.559 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
https://wpscan.com/vulnerability/dd48624a-1781-419c-a3c4-1e3eaf5e2c1b
https://www.wordfence.com/threat-intel/vulnerabilities/id/1ce15d38-c5bc-441b-976a-60a3e90b5a30