Lucene search

K
wpexploitDmitriiWPEX-ID:CA954EC6-6EBD-4D72-A323-570474E2E339
HistoryAug 14, 2023 - 12:00 a.m.

Advanced File Manager < 5.1.1 - Admin+ Arbitrary File/Folder Access

2023-08-1400:00:00
Dmitrii
31
file manager
admin+ access
multisite installation
arbitrary access

5.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.3%

Description The plugin does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

On a multisite installation, log in as a site admin. Notice that you are able to manage files on the server using this plugin.

5.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.3%

Related for WPEX-ID:CA954EC6-6EBD-4D72-A323-570474E2E339