4.1

CVE-2025-2048

Exploit

Lana Downloads Manager <= 1.9.0 - Authenticated (Admin+) Arbitrary File Download

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server
Mögliche Gegenmaßnahme
Lana Downloads Manager: Update to version 1.10.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Lana Downloads Manager
Version *-1.9.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LanaLana Downloads Manager SwPlatformwordpress Version < 1.10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.536
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.1 2.3 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.