PT-2018-6624 · WordPress · Download Manager
Mallory Adams
·
Publicado
2018-01-16
·
Atualizado
2025-03-21
·
CVE-2017-18032
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WordPress download-manager plugin versions prior to 2.9.52
Description:
The issue concerns a security problem where an attacker can exploit the
id parameter in a wpdm generate password action to wp-admin/admin-ajax.php API endpoint, leading to a potential XSS attack.Recommendations:
For versions prior to 2.9.52, update the download-manager plugin to version 2.9.52 or later to resolve the issue. As a temporary workaround, consider restricting access to the
wp-admin/admin-ajax.php API endpoint or avoiding the use of the id parameter in the wpdm generate password action until the update is applied.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Download Manager