Ninjateam

Filester

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.58%
  • Veröffentlicht 13.08.2025 03:42:04
  • Zuletzt bearbeitet 13.08.2025 17:33:46

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerabilit...

  • EPSS 0.07%
  • Veröffentlicht 19.12.2024 12:15:05
  • Zuletzt bearbeitet 05.03.2025 18:25:53

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in all versions up to, and including, 1.8.6. This makes it possible for au...

  • EPSS 2.06%
  • Veröffentlicht 28.11.2024 09:15:05
  • Zuletzt bearbeitet 26.02.2025 19:54:38

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with...

  • EPSS 1.81%
  • Veröffentlicht 28.11.2024 09:15:05
  • Zuletzt bearbeitet 26.02.2025 19:54:38

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes it possible for authenticated attackers, with Administrator-le...

  • EPSS 0.71%
  • Veröffentlicht 03.08.2024 09:15:30
  • Zuletzt bearbeitet 10.04.2025 20:35:21

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it poss...

Exploit
  • EPSS 3.72%
  • Veröffentlicht 16.10.2023 20:15:17
  • Zuletzt bearbeitet 23.04.2025 17:16:48

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 16.10.2023 20:15:17
  • Zuletzt bearbeitet 21.11.2024 08:36:07

The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users.

Exploit
  • EPSS 6.28%
  • Veröffentlicht 16.10.2023 09:15:11
  • Zuletzt bearbeitet 23.04.2025 17:16:47

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET reques...