Download Manager <= 3.2.38 - Unauthenticated Brute Force of File Master Key

2022-03-16 00:00
Diogo Real

Strategic Overview

Status
Patched in 3.2.39
Affected PluginDownload Manager
Affected Version< 3.2.39
CVSS7.5High
CVECVE-2022-0828
View all Download Manager vulnerabilities

Vulnerability Overview

The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

Technical Analysis

REMEDIATION: Update to version 3.2.39, or a newer patched version --- IDENTIFIER: CWE-326 (Inadequate Encryption Strength) The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C