PT-2021-11017 · WordPress · Cm Download Manager
Published
2021-07-07
·
Updated
2021-07-12
·
CVE-2020-24146
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
CM Download Manager plugin version 2.7.0
Description:
The issue allows authorized users to delete arbitrary files and possibly cause a denial of service. This is achieved via the
fileName parameter in a deletescreenshot action.Recommendations:
For CM Download Manager plugin version 2.7.0, consider restricting access to the deletescreenshot action to prevent unauthorized file deletion until a patch is available. Avoid using the
fileName parameter in the affected action until the issue is resolved.Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cm Download Manager