cleantalk
Vulnerabilities and Security Researches

Download Manager, CVE-2022-0828

CVE, Research URL

CVE-2022-0828

Application

Download Manager

Published on
Apr 11, 2022
Research Description
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
Affected versions
max 2.9.46.
Status
vulnerable