The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.
References
Configurations
History
No history.
Information
Published : 2024-06-29 05:15
Updated : 2024-11-21 09:47
NVD link : CVE-2024-5598
Mitre link : CVE-2024-5598
CVE.ORG link : CVE-2024-5598
JSON object : View
Products Affected
advancedfilemanager
- advanced_file_manager
CWE