cve/2023/CVE-2023-5105.md

18 lines
747 B
Markdown
Raw Normal View History

2024-05-28 08:49:17 +00:00
### [CVE-2023-5105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5105)
![](https://img.shields.io/static/v1?label=Product&message=Frontend%20File%20Manager%20Plugin&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%2022.6%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%20Information%20Exposure&color=brighgreen)
### Description
The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`
### POC
#### Reference
- https://wpscan.com/vulnerability/d40c7108-bad6-4ed3-8539-35c0f57e62cc
#### Github
No PoCs found on GitHub currently.