cleantalk
Vulnerabilities and Security Researches

Download Manager, CVE-2022-0828

CVE, Research URL

CVE-2022-0828

Application

Download Manager

Published on
Apr 11, 2022
Research Description
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
Affected versions
Min -, max 2.9.46.
Status
vulnerable