CVE-2022-1119
Simple File List <= 3.2.7 - Arbitrary File Download
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.
El plugin Simple File List de WordPress es vulnerable a una descarga de archivos arbitrarios por medio del parámetro eeFile que es encontrado en el archivo ~/includes/ee-downloader.php debido a una falta de controles que hace posible que atacantes no autenticados suministren una ruta a un archivo que posteriormente será descargado, en versiones hasta 3.2.7 incluyéndola
*Credits:
Bernardo Rodrigues, Admavidhya N
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-05-23 CVE Published
- 2022-03-28 CVE Reserved
- 2022-07-30 First Exploit
- 2024-08-02 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/ff21241d-e488-4460-b8c2-d5a070c8c107?source=cve |
URL | Date | SRC |
---|---|---|
https://github.com/z92g/CVE-2022-1119 | 2022-07-30 | |
https://docs.google.com/document/d/1qIZXTzEpI4tO6832vk1KfsSAroT0FY2l--THlhJ8z3c/edit | 2024-08-02 | |
https://wpscan.com/vulnerability/075a3cc5-1970-4b64-a16f-3ec97e22b606 | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/browser/simple-file-list/trunk/includes/ee-downloader.php?rev=2071880 | 2024-01-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simplefilelist Search vendor "Simplefilelist" | Simple-file-list Search vendor "Simplefilelist" for product "Simple-file-list" | < 3.2.8 Search vendor "Simplefilelist" for product "Simple-file-list" and version " < 3.2.8" | wordpress |
Affected
|