cleantalk
Vulnerabilities and Security Researches

CM Download Manager – Document and File Management, CVE-2024-1962

CVE, Research URL

CVE-2024-1962

Published on
Mar 25, 2024
Research Description
The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack
Affected versions
Min -, max 2.9.1.
Status
vulnerable