CVE-2023-3814: Advanced File Manager < 5.1.1 - Admin+ Arbitrary File/Folder Access
Published Sep 4, 2023
·Updated
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.
Affected Software
1 affected component
Advancedfilemanager Advanced File Manager Wordpress<5.1.1
Event History
Sep 4, 2023
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Advanced File Manager WordPress plugin?
The vulnerability ID for the Advanced File Manager WordPress plugin is CVE-2023-3814.
2
What is the severity level of CVE-2023-3814?
The severity level of CVE-2023-3814 is medium with a severity value of 4.9.
3
What is the affected software by CVE-2023-3814?
The affected software by CVE-2023-3814 is the Advanced File Manager WordPress plugin version up to and excluding 5.1.1.
4
What can an attacker do with CVE-2023-3814?
An attacker can list and read arbitrary files and folders on the server using CVE-2023-3814.
5
How can I fix the vulnerability in Advanced File Manager WordPress plugin?
To fix the vulnerability in Advanced File Manager WordPress plugin, update to version 5.1.1 or newer.