NA

CVE-2023-4827

Published: 16/10/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The File Manager Pro WordPress plugin prior to 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows malicious users to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.

Vulnerable Product Search on Vulmon Subscribe to Product

ninjateam filester