Описание
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
Ссылки
- ExploitThird Party AdvisoryURL Repurposed
- ExploitThird Party AdvisoryURL Repurposed
Уязвимые конфигурации
Конфигурация 1Версия до 6.4 (включая)
cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 98%
0.51624
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-552
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
EPSS
Процентиль: 98%
0.51624
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-552