CVE-2022-2392
Lana Downloads Manager < 1.8.0 - Contributor+ Arbitrary File Download
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
El plugin Lana Downloads Manager de WordPress versiones anteriores a 1.8.0, está afectado por una vulnerabilidad de descarga de archivos arbitraria que puede ser explotada por usuarios con permisos "Contributor" o superiores.
The Lana Downloads Manager plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers, with contributor level permissions and above, to download arbitrary files on the affected site's server thus leaking sensitive information.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-12 CVE Reserved
- 2022-08-01 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/5001ed18-858e-4c9d-9d7b-a1305fcdf61b | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lana Search vendor "Lana" | Lana Downloads Manager Search vendor "Lana" for product "Lana Downloads Manager" | < 1.8.0 Search vendor "Lana" for product "Lana Downloads Manager" and version " < 1.8.0" | wordpress |
Affected
|