CVE-2020-24312: High severity webdesi9 file manager vulnerability
Published Aug 26, 2020
·Updated
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fmbackups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
Affected Software
2 affected components
Webdesi9 File Manager Wordpress<=6.4
Filemanagerpro File Manager Wordpress<=6.4
Event History
Aug 26, 2020
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-24312.
2
What is the title of the vulnerability?
The title of the vulnerability is 'mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory.'
3
What is the severity of CVE-2020-24312?
The severity of CVE-2020-24312 is high.
4
How does CVE-2020-24312 affect the software?
CVE-2020-24312 affects the Webdesi9 File Manager plugin v6.4 and lower for WordPress.
5
What can unauthenticated users do due to CVE-2020-24312?
Unauthenticated users can browse and download any site backups, including full database backups, that the plugin has taken.