CVE-2022-3076Unrestricted File Upload in CM Download Manager

Severity
7.2HIGHNVD
EPSS
1.1%
top 22.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Latest updateSep 27

Description

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9q5w-5rhq-cpgp: The CM Download Manager WordPress plugin before 22022-09-27
CVEList
CM Download Manager < 2.8.6 - Admin+ Arbitrary File Upload2022-09-26