CVE-2022-2926
Summary
| CVE | CVE-2022-2926 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-26 13:15:00 UTC |
| Updated | 2022-09-28 16:30:00 UTC |
| Description | The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Download Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Download Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path Traversal WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Raad Haddad of Cloudyrion GmbH
There are currently no legacy QID mappings associated with this CVE.