CVE-2022-3076
CM Download Manager < 2.8.6 - Admin+ Arbitrary File Upload
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Sep 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · CM Download ManagerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →