PT-2022-20298 · WordPress · Cm Download Manager

Mika

·

Published

2022-09-26

·

Updated

2022-09-27

·

CVE-2022-3076

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CM Download Manager WordPress plugin versions prior to 2.8.6
Description The issue allows high privilege users, such as admins, to upload arbitrary files by setting any extension via the plugin's setting. This could be exploited by admins of multisite blogs to upload PHP files, for example.
Recommendations For CM Download Manager WordPress plugin versions prior to 2.8.6, update to version 2.8.6 or later to resolve the issue. As a temporary workaround, consider restricting the upload functionality to prevent high privilege users from uploading arbitrary files until the update is applied.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3076

Affected Products

Cm Download Manager