4.1

CVE-2025-2048

Exploit

Lana Downloads Manager < 1.10.0 - Admin+ Arbitrary File Download via Path Traversal

Lana Downloads Manager <= 1.9.0 - Authenticated (Admin+) Arbitrary File Download

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server
Mögliche Gegenmaßnahme
Lana Downloads Manager: Update to version 1.10.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LanaLana Downloads Manager SwPlatformwordpress Version < 1.10.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Lana Downloads Manager
Version *-1.9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.359
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.1 2.3 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://wpscan.com/vulnerability/05c664e8-110e-4a31-8377-41a0422508a7/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/41b4a0c4-84f6-4c7a-926a-5f436c710759
Third Party Advisory