CVE-2023-5105: Frontend File Manager < 22.6 - Editor+ Arbitrary File Download
Published Dec 4, 2023
·Updated
The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as wp-config.php
Affected Software
1 affected component
Najeebmedia Frontend File Manager Plugin Wordpress<22.6
Event History
Dec 4, 2023
CVE Published
09:27 PM
Data Sourced
09:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-5105.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Frontend File Manager < 22.6 - Editor+ Arbitrary File Download'.
3
What is the severity of CVE-2023-5105?
The severity of CVE-2023-5105 is medium with a severity value of 6.5.
4
How does CVE-2023-5105 affect the affected software?
CVE-2023-5105 affects the Frontend File Manager Plugin WordPress plugin before version 22.6.
5
What is the CWE of CVE-2023-5105?
The CWE of CVE-2023-5105 is CWE-200 and CWE-22.