ZeroHour

CVE-2022-0828

PoC
CVSS 3.1
7.5 high
EPSS
2%p73
Published
()
Modified
Description

The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

Vendors
w3eden
Products
download manager
Ecosystems
WordPress
Weakness
CWE-338
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.