The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vasyltech
Vasyltech advanced Access Manager |
|
CPEs | cpe:2.3:a:vasyltech:advanced_access_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Vasyltech
Vasyltech advanced Access Manager |
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Advanced Access Manager Project
Advanced Access Manager Project advanced Access Manager |
|
CPEs | cpe:2.3:a:advanced_access_manager_project:advanced_access_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Advanced Access Manager Project
Advanced Access Manager Project advanced Access Manager |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php | |
Title | Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:32.214Z
Updated: 2024-10-16T18:05:50.381Z
Reserved: 2024-10-15T17:42:48.469Z
Link: CVE-2019-25213
Vulnrichment
Updated: 2024-10-16T17:58:36.931Z
NVD
Status : Analyzed
Published: 2024-10-16T07:15:05.790
Modified: 2024-10-30T18:20:42.563
Link: CVE-2019-25213
Redhat
No data.