WordPress Plugin Vulnerabilities

Download Manager < 3.2.71 - Broken Access Controls

Description

The plugin does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

Proof of Concept

Affects Plugins

Fixed in 3.2.71

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Johan Kragt
Submitter
Johan Kragt
Verified
Yes

Timeline

Publicly Published
2023-05-08 (about 2 years ago)
Added
2023-05-08 (about 2 years ago)
Last Updated
2023-05-08 (about 2 years ago)

Other