CVE-2023-4827 β€” Cross-Site Request Forgery in Filester

Severity
8.8HIGHNVD
EPSS
6.3%
top 9.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16

Description

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

β–ΆNVDninjateam/filester< 1.8

πŸ”΄Vulnerability Details

2
CVEList
File Manager Pro < 1.8 - Remote Code Execution via CSRF↗2023-10-16
β–Ά
GHSA
GHSA-3743-q7xh-2hv2: The File Manager Pro WordPress plugin before 1β†—2023-10-16
β–Ά
CVE-2023-4827 β€” Cross-Site Request Forgery in Filester | cvebase