The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.
History

Tue, 03 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Modalweb
Modalweb advanced File Manager
CPEs cpe:2.3:a:modalweb:advanced_file_manager:*:*:*:*:*:*:*:*
Vendors & Products Modalweb
Modalweb advanced File Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
Description The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title Advanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-03T14:34:29.866Z

Updated: 2024-12-03T15:56:04.491Z

Reserved: 2024-11-18T22:42:04.474Z

Link: CVE-2024-11391

cve-icon Vulnrichment

Updated: 2024-12-03T15:55:59.354Z

cve-icon NVD

Status : Received

Published: 2024-12-03T15:15:09.973

Modified: 2024-12-03T15:15:09.973

Link: CVE-2024-11391

cve-icon Redhat

No data.