PT-2018-6624 · WordPress · Download Manager

Mallory Adams

·

Publicado

2018-01-16

·

Atualizado

2025-03-21

·

CVE-2017-18032

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WordPress download-manager plugin versions prior to 2.9.52
Description: The issue concerns a security problem where an attacker can exploit the id parameter in a wpdm generate password action to wp-admin/admin-ajax.php API endpoint, leading to a potential XSS attack.
Recommendations: For versions prior to 2.9.52, update the download-manager plugin to version 2.9.52 or later to resolve the issue. As a temporary workaround, consider restricting access to the wp-admin/admin-ajax.php API endpoint or avoiding the use of the id parameter in the wpdm generate password action until the update is applied.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-18032

Produtos afetados

Download Manager