2021-01-02 04:56:15 +00:00
id : CVE-2020-24312
2020-09-30 14:30:06 +00:00
info :
name : WordPress Plugin File Manager (wp-file-manager) Backup Disclosure
author : x1m_martijn
severity : high
2021-03-18 13:13:45 +00:00
description : |
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
2023-09-06 12:22:36 +00:00
remediation : |
Update the WordPress Plugin File Manager (wp-file-manager) to the latest version to mitigate the backup disclosure vulnerability.
2021-08-19 13:15:35 +00:00
reference :
- https://zeroaptitude.com/zerodetail/wordpress-plugin-bug-hunting-part-1/
- https://nvd.nist.gov/vuln/detail/CVE-2020-24312
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 7.5
2021-09-10 11:26:40 +00:00
cve-id : CVE-2020-24312
cwe-id : CWE-552
2023-10-14 11:27:55 +00:00
epss-score : 0.01622
2023-11-14 14:37:18 +00:00
epss-percentile : 0.8605
2023-09-06 12:22:36 +00:00
cpe : cpe:2.3:a:webdesi9:file_manager:*:*:*:*:*:wordpress:*:*
2023-04-28 08:11:21 +00:00
metadata :
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : webdesi9
product : file_manager
2023-09-06 12:22:36 +00:00
framework : wordpress
2023-07-11 19:49:27 +00:00
tags : cve,cve2020,wordpress,backups,plugin
2020-09-30 14:30:06 +00:00
2023-04-27 04:28:59 +00:00
http :
2020-09-30 14:30:06 +00:00
- method : GET
path :
- '{{BaseURL}}/wp-content/uploads/wp-file-manager-pro/fm_backup/'
2021-08-10 01:43:58 +00:00
2020-09-30 14:30:06 +00:00
matchers-condition : and
matchers :
2020-09-30 14:44:12 +00:00
- type : word
words :
2021-08-10 01:43:58 +00:00
- 'Index of'
2021-08-10 14:43:14 +00:00
- 'wp-content/uploads/wp-file-manager-pro/fm_backup'
- 'backup_'
2022-01-04 19:34:16 +00:00
condition : and
2023-07-11 19:49:27 +00:00
- type : status
status :
- 200
2023-11-14 05:56:48 +00:00
# digest: 4a0a00473045022078bd8d954a276a44eaf3d2b13bbdeb9e3a08cceaac204ad348cf84b784114ed7022100d274283a165d3044e35dbe1ccc08feef61d4bbc2bd93395dd8ed2f39f108d459:922c64590222798bb761d5b6d8e72950