CVE-2024-0761
05.02.2024, 22:16
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.Enginsight
Vendor | Product | Version |
---|---|---|
filemanagerpro | file_manager | 𝑥 ≤ 7.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References