CVE-2023-1524: Download Manager < 3.2.71 - Broken Access Controls
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1524?
The severity of CVE-2023-1524 is medium with a CVSSv3 score of 6.5.
Does the Download Manager WordPress plugin version 3.2.71 have the vulnerability?
Yes, the Download Manager WordPress plugin version 3.2.71 is affected by CVE-2023-1524.
What is the impact of CVE-2023-1524?
CVE-2023-1524 allows an attacker to download any password-protected file on the server without authentication.
How can I fix the vulnerability in the Download Manager WordPress plugin?
To fix the vulnerability, update the Download Manager plugin to a version greater than or equal to 3.2.71.
Is there any additional information about CVE-2023-1524?
For more information about CVE-2023-1524, you can refer to the following link: [Reference](https://wpscan.com/vulnerability/3802d15d-9bfd-4762-ab8a-04475451868e)