6.5
CVE-2022-2392
- EPSS 0.46%
- Veröffentlicht 22.08.2022 15:15:15
- Zuletzt bearbeitet 21.11.2024 07:00:53
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Lana Downloads Manager <= 1.7.1 - Authenticated (Contributor+) Arbitrary File Download
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
Mögliche Gegenmaßnahme
Lana Downloads Manager: Update to version 1.8.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Lana Downloads Manager
Version
*-1.7.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lana ≫ Lana Downloads Manager SwPlatformwordpress Version < 1.8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.636 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.