CVE-2022-3076
Summary
| CVE | CVE-2022-3076 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-26 13:15:00 UTC |
| Updated | 2022-09-27 04:37:00 UTC |
| Description | The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cminds | Cm Download Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CM Download Manager < 2.8.6 - Admin+ Arbitrary File Upload WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Mika
There are currently no legacy QID mappings associated with this CVE.