Description
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8209 | The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php. |
References
History
Fri, 18 Oct 2024 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filemanagerpro
Filemanagerpro file Manager |
|
| CPEs | cpe:2.3:a:filemanagerpro:file_manager:2.9:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webdesi9
Webdesi9 file Manager |
Filemanagerpro
Filemanagerpro file Manager |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:24:32.343Z
Reserved: 2018-09-02T00:00:00.000Z
Link: CVE-2018-16363
No data.
Status : Modified
Published: 2018-09-07T22:29:01.947
Modified: 2024-11-21T03:52:36.297
Link: CVE-2018-16363
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD