Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0403

Опубликовано: 04 апр. 2022
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpjos:library_file_manager:*:*:*:*:*:wordpress:*:*
Версия до 5.2.3 (исключая)

EPSS

Процентиль: 52%
0.0029
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.1
github
почти 4 года назад

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

EPSS

Процентиль: 52%
0.0029
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-434