CVE-2022-3124
Frontend File Manager < 21.3 - Unauthenticated File Renaming
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server
El plugin Frontend File Manager de WordPress versiones anteriores a 21.3, permite a cualquier usuario no autenticado renombrar los archivos descargados por los usuarios. Además, debido a una falta de comprobación en el nombre de archivo de destino, esto podría permitirles cambiar el contenido de archivos arbitrarios en el servidor web
The Frontend File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lacking authentication in versions up to, and including, 9.8. This makes it possible for unauthenticated attackers to rename uploaded files on the site.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-05 CVE Reserved
- 2022-09-07 CVE Published
- 2024-04-25 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/00f76765-95af-4dbc-8c37-f1b15a0e8608 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Najeebmedia Search vendor "Najeebmedia" | Frontend File Manager Search vendor "Najeebmedia" for product "Frontend File Manager" | < 21.3 Search vendor "Najeebmedia" for product "Frontend File Manager" and version " < 21.3" | wordpress |
Affected
|