Najeebmedia

Frontend File Manager

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 69.4%
  • Veröffentlicht 16.10.2024 08:15:02
  • Zuletzt bearbeitet 30.10.2024 21:12:53

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_...

  • EPSS 0.28%
  • Veröffentlicht 17.03.2024 17:15:06
  • Zuletzt bearbeitet 27.02.2025 03:34:34

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7.

Exploit
  • EPSS 1.45%
  • Veröffentlicht 03.10.2022 14:15:20
  • Zuletzt bearbeitet 21.11.2024 07:18:52

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the serve...

Exploit
  • EPSS 5.71%
  • Veröffentlicht 03.10.2022 14:15:19
  • Zuletzt bearbeitet 21.11.2024 07:18:52

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the conte...