The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Feb 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjateam filester
|
|
| CPEs | cpe:2.3:a:ninjateam:filester:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ninjateam filester
|
Sat, 04 Jan 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. |
| Title | File Manager Pro – Filester <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload | File Manager Pro – Filester <= 1.8.6- Authenticated (Subscriber+) Arbitrary File Upload |
Fri, 29 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjateam
Ninjateam filemanager Pro-filester |
|
| CPEs | cpe:2.3:a:ninjateam:filemanager_pro-filester:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ninjateam
Ninjateam filemanager Pro-filester |
|
| Metrics |
ssvc
|
Thu, 28 Nov 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. | |
| Title | File Manager Pro – Filester <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-28T08:47:31.273Z
Updated: 2025-01-06T17:45:20.183Z
Reserved: 2024-08-21T22:44:39.513Z
Link: CVE-2024-8066
Updated: 2024-11-29T15:29:49.339Z
Status : Analyzed
Published: 2024-11-28T09:15:05.547
Modified: 2025-02-26T19:54:38.100
Link: CVE-2024-8066
No data.
ReportizFlow