216.73.217.22

CVE-2024-7627

· Published 05/09/2024 03:15 · Modified 11/09/2024 16:31

Labels: CVE-2024-7627 2024-09-05CVE-2024-7627CWE-362CWE-94[email protected]

Essential information

Published
05/09/2024 03:15
Modified
11/09/2024 16:31
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bitapps / file manager cpe:2.3:a:bitapps:file_manager:*:*:*:*:*:wordpress:*:*

References