CVE-2022-2392

The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lana:lana_downloads_manager:*:*:*:*:*:wordpress:*:*

History

25 Aug 2022, 02:53

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/5001ed18-858e-4c9d-9d7b-a1305fcdf61b - (MISC) https://wpscan.com/vulnerability/5001ed18-858e-4c9d-9d7b-a1305fcdf61b - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Lana lana Downloads Manager
Lana
CPE cpe:2.3:a:lana:lana_downloads_manager:*:*:*:*:*:wordpress:*:*

22 Aug 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-22 15:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-2392

Mitre link : CVE-2022-2392

CVE.ORG link : CVE-2022-2392


JSON object : View

Products Affected

lana

  • lana_downloads_manager
CWE
CWE-552

Files or Directories Accessible to External Parties