CVE-2024-5598

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advancedfilemanager:advanced_file_manager:*:*:*:*:*:wordpress:*:*

History

01 Aug 2024, 16:50

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Advancedfilemanager
Advancedfilemanager advanced File Manager
CPE cpe:2.3:a:advancedfilemanager:advanced_file_manager:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/file-manager-advanced/trunk/application/class_fma_connector.php#L13 - () https://plugins.trac.wordpress.org/browser/file-manager-advanced/trunk/application/class_fma_connector.php#L13 - Issue Tracking
References () https://plugins.trac.wordpress.org/changeset/3107587/ - () https://plugins.trac.wordpress.org/changeset/3107587/ - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/9d4ff5ed-8857-46b8-942b-ac0f47880a95?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/9d4ff5ed-8857-46b8-942b-ac0f47880a95?source=cve - Third Party Advisory

01 Jul 2024, 12:37

Type Values Removed Values Added
Summary
  • (es) El complemento Advanced File Manager para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 5.2.4 incluida a través de la función 'fma_local_file_system'. Esto hace posible que atacantes no autenticados extraigan datos confidenciales, incluidas copias de seguridad u otra información confidencial, si los archivos se han movido a la carpeta Papelera integrada.

29 Jun 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-29 05:15

Updated : 2024-08-01 16:50


NVD link : CVE-2024-5598

Mitre link : CVE-2024-5598

CVE.ORG link : CVE-2024-5598


JSON object : View

Products Affected

advancedfilemanager

  • advanced_file_manager