First published: Wed Aug 26 2020(Updated: )
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webdesi9 File Manager | <=6.4 | |
<=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-24312.
The title of the vulnerability is 'mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory.'
The severity of CVE-2020-24312 is high.
CVE-2020-24312 affects the Webdesi9 File Manager plugin v6.4 and lower for WordPress.
Unauthenticated users can browse and download any site backups, including full database backups, that the plugin has taken.