Lucene search

K
cvePatchstackCVE-2024-32131
HistoryMay 17, 2024 - 9:15 a.m.

CVE-2024-32131

2024-05-1709:15:35
CWE-200
Patchstack
web.nvd.nist.gov
41
cve-2024-32131
unauthorized actor
functionality bypass
nvd
download manager
w3 eden inc.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.

Affected configurations

Vulners
Node
w3_eden_inc.download_managerRange3.2.82wordpress
VendorProductVersionCPE
w3_eden_inc.download_manager*cpe:2.3:a:w3_eden_inc.:download_manager:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "download-manager",
    "product": "Download Manager",
    "vendor": "W3 Eden Inc.",
    "versions": [
      {
        "changes": [
          {
            "at": "3.2.83",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "3.2.82",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%