Логотип exploitDog
bind:CVE-2018-25105
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-25105

Количество 2

Количество 2

nvd логотип

CVE-2018-25105

больше 1 года назад

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-9f9w-6h4v-8h8v

больше 1 года назад

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-25105

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-9f9w-6h4v-8h8v

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.

CVSS3: 9.8
2%
Низкий
больше 1 года назад

Уязвимостей на страницу