cve/2022/CVE-2022-2392.md

18 lines
784 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-2392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2392)
![](https://img.shields.io/static/v1?label=Product&message=Lana%20Downloads%20Manager&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.8.0%3C%201.8.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-552%20Files%20or%20Directories%20Accessible%20to%20External%20Parties&color=brighgreen)
### Description
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
### POC
#### Reference
- https://wpscan.com/vulnerability/5001ed18-858e-4c9d-9d7b-a1305fcdf61b
#### Github
No PoCs found on GitHub currently.