CVE-2022-3126
Summary
| CVE | CVE-2022-3126 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-17 12:15:00 UTC |
| Updated | 2022-10-21 16:13:00 UTC |
| Description | The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Najeebmedia | Frontend File Manager Plugin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Frontend File Manager < 21.4 - File Upload via CSRF WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Raad Haddad of Cloudyrion GmbH
There are currently no legacy QID mappings associated with this CVE.