CVE-2022-2168: fallo en Download Manager
Download Manager < 3.2.44 - Reflected Cross-Site Scripting
Publicada el · Actualizada el
18Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 1.4%
probabilidad de explotación
1.4%top 29% de las CVE
explotación observada
noninguna fuente lo reporta
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
Productos afectados
Unknown · Download ManagerCVEs relacionadas — Download Manager
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-6421HIGHDownload Manager < 3.2.83 - Unauthenticated Protected File Download Password LeakEPSS 2.4%CVE-2022-2926MEDIUMDownload Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path TraversalEPSS 1.7%CVE-2022-0828—Download Manager < 3.2.39 - Unauthenticated brute force of files master keyEPSS 1.5%CVE-2021-25087—Wordpress Download Manager < 3.2.25 - Sensitive Information DisclosureEPSS 1.5%CVE-2021-25069—WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSSEPSS 1.5%CVE-2022-2362—Download Manager < 3.2.50 - Bypass IP Address Blocking RestrictionEPSS 1.2%