PT-2022-13157 · WordPress+1 · Libra File Manager+1

Luan Pedersni

·

Published

2022-04-04

·

Updated

2022-04-11

·

CVE-2022-0403

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Library File Manager WordPress plugin versions prior to 5.2.3
Description The issue affects the Library File Manager WordPress plugin due to its use of an outdated elFinder library version, which lacks authorization and CSRF checks in its connector AJAX action. This allows any authenticated user to call the action, potentially creating, uploading, or deleting arbitrary files and folders.
Recommendations For versions prior to 5.2.3, update to version 5.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the elFinder library's connector AJAX action to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0403

Affected Products

Libra File Manager
Elfinder