6.5
CVE-2022-2392
- EPSS 0.91%
- Veröffentlicht 22.08.2022 15:15:15
- Zuletzt bearbeitet 21.11.2024 07:00:53
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Lana Downloads Manager < 1.8.0 - Contributor+ Arbitrary File Download
Lana Downloads Manager <= 1.7.1 - Authenticated (Contributor+) Arbitrary File Download
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
Mögliche Gegenmaßnahme
Lana Downloads Manager: Update to version 1.8.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lana ≫ Lana Downloads Manager SwPlatformwordpress Version < 1.8.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Lana Downloads Manager
Version
*-1.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.91% | 0.553 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
https://wpscan.com/vulnerability/5001ed18-858e-4c9d-9d7b-a1305fcdf61b
https://www.wordfence.com/threat-intel/vulnerabilities/id/9abae49f-b396-4684-8dd5-0b5593069861