PT-2022-16180 · WordPress · Wsm Downloader
Raad Haddad
·
Published
2022-08-08
·
Updated
2022-08-11
·
CVE-2022-2367
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WSM Downloader WordPress plugin version 1.4.0
Description
The issue arises from the lack of proper validation of the
link parameter, allowing bypass of restrictions on downloading images or files from specific popular websites.Recommendations
For version 1.4.0, consider restricting access to the
link parameter until a patch is available, or update to a version that properly validates this parameter to prevent bypass of download restrictions.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wsm Downloader