The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Fri, 29 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ninjateam
Ninjateam filemanager Pro-filester |
|
CPEs | cpe:2.3:a:ninjateam:filemanager_pro-filester:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ninjateam
Ninjateam filemanager Pro-filester |
|
Metrics |
ssvc
|
Thu, 28 Nov 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | File Manager Pro – Filester <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-28T08:47:31.273Z
Updated: 2024-11-29T15:29:55.300Z
Reserved: 2024-08-21T22:44:39.513Z
Link: CVE-2024-8066
Vulnrichment
Updated: 2024-11-29T15:29:49.339Z
NVD
Status : Received
Published: 2024-11-28T09:15:05.547
Modified: 2024-11-28T09:15:05.547
Link: CVE-2024-8066
Redhat
No data.