← volver
CVE-2024-1231

CM Download and File Manager < 2.9.0 - Download Unpublish via CSRF

CVSS 6.8 MEDIUMEPSS 0.2%
The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →