CVE-2023-6421: high-severity vulnerability in Download Manager
Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak
Published · Updated
36Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.5epss 2.4%
exploitation probability
2.4%top 16% of all CVEs
observed exploitation
nono source reports it
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Unknown · Download ManagerRelated CVEs — Download Manager
In the same product, most dangerous first.
CVE-2022-2926MEDIUMDownload Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path TraversalEPSS 1.7%CVE-2022-0828—Download Manager < 3.2.39 - Unauthenticated brute force of files master keyEPSS 1.5%CVE-2021-25087—Wordpress Download Manager < 3.2.25 - Sensitive Information DisclosureEPSS 1.5%CVE-2021-25069—WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSSEPSS 1.5%CVE-2022-2168—Download Manager < 3.2.44 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-2362—Download Manager < 3.2.50 - Bypass IP Address Blocking RestrictionEPSS 1.2%