PT-2023-17052 · WordPress · Download Manager

·

CVE-2023-1524

·

Published

2023-05-30

·

Updated

2025-01-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Download Manager WordPress plugin versions prior to 3.2.71
Description The issue concerns inadequate password validation for password-protected files. When a password is validated, a master key is generated and exposed to the user. This master key can be used to download any password-protected file on the server, allowing unauthorized access to files with the knowledge of just one file's password.
Recommendations For versions prior to 3.2.71, update to version 3.2.71 or later to resolve the issue. As a temporary workaround, consider restricting access to password-protected files until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-1524

Affected Products

Download Manager