The plugin does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Create a new download on: https://target-site/wp-admin/post-new.php?post_type=dlm_download Add the following payload to the "File URL(s); note: only enter multiple URLs in here if you want to use file mirrors" field when creating a new Download: php://filter/convert.base64-encode/resource=/var/www/vhosts/developerspace.de/httpdocs/blog/wp-config.php Navigate to the newly created download page.
Raad Haddad of Cloudyrion GmbH
Raad Haddad of Cloudyrion GmbH
Yes
2022-09-19 (about 6 months ago)
2022-09-19 (about 6 months ago)
2022-09-19 (about 6 months ago)