The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bitapps
Bitapps file Manager |
|
CPEs | cpe:2.3:a:bitapps:file_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Bitapps
Bitapps file Manager |
|
Metrics |
ssvc
|
Sat, 05 Oct 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting. | |
Title | Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-05T06:44:10.696Z
Updated: 2024-10-07T15:57:49.035Z
Reserved: 2024-09-11T21:44:52.570Z
Link: CVE-2024-8743
Vulnrichment
Updated: 2024-10-07T15:22:29.971Z
NVD
Status : Awaiting Analysis
Published: 2024-10-05T07:15:12.297
Modified: 2024-10-07T17:48:28.117
Link: CVE-2024-8743
Redhat
No data.