CVE-2020-24312
26.08.2020, 13:15
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.Enginsight
Vendor | Product | Version |
---|---|---|
filemanagerpro | file_manager | 𝑥 ≤ 6.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration