Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-1524

Опубликовано: 30 мая 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*
Версия до 3.2.71 (исключая)

EPSS

Процентиль: 40%
0.00183
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
github
больше 2 лет назад

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

EPSS

Процентиль: 40%
0.00183
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo