PT-2024-39184 · WordPress · Advanced File Manager

Siunam

+1

·

Published

2024-09-26

·

Updated

2024-10-01

·

CVE-2024-8704

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Advanced File Manager plugin for WordPress versions up to, and including, 5.2.8
Description: The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion via the fma locale parameter. This allows authenticated attackers with Administrator-level access and above to include and execute arbitrary files on the server, enabling the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Recommendations: For versions up to, and including, 5.2.8, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the fma locale parameter to minimize the risk of exploitation. Restrict file uploads to only necessary file types and ensure proper validation and sanitization of uploaded files. Limit Administrator-level access to only trusted users to reduce the attack surface. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-8704

Affected Products

Advanced File Manager