Download Manager <= 3.2.38 - Unauthenticated Brute Force of File Master Key
2022-03-16 00:00
Diogo RealStrategic Overview
StatusPatched in 3.2.39
Affected PluginDownload Manager
Affected Version
< 3.2.39CVSS7.5High
CVE
CVE-2022-0828Vulnerability Overview
The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
Technical Analysis
REMEDIATION: Update to version 3.2.39, or a newer patched version --- IDENTIFIER: CWE-326 (Inadequate Encryption Strength) The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C