CVE-2022-3126
Frontend File Manager < 21.4 - File Upload via CSRF
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf
El plugin Frontend File Manager de WordPress versiones anteriores a 21.4, no presenta una comprobación de tipo SRF cuando son subidos archivos, lo que podrÃa permitir a atacantes hacer que usuarios registrados suban archivos en su nombre
The "Frontend File Manager Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 21.2. This is due to missing or incorrect nonce validation on the wpfm_upload_file function. This makes it possible for unauthenticated attackers to upload files on behalf of other users, via forged request granted they can trick such a user into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-05 CVE Reserved
- 2022-09-26 CVE Published
- 2024-05-09 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/7db363bf-7bef-4d47-9963-c30d6fdd2fb8 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Najeebmedia Search vendor "Najeebmedia" | Frontend File Manager Plugin Search vendor "Najeebmedia" for product "Frontend File Manager Plugin" | < 21.4 Search vendor "Najeebmedia" for product "Frontend File Manager Plugin" and version " < 21.4" | wordpress |
Affected
|