Access Control Weakness in W3 Eden Download Manager
CVE-2024-56217
4.3MEDIUM
Key Information:
- Vendor
- W3 Eden, Inc.
- Status
- Download Manager
- Vendor
- CVE Published:
- 31 December 2024
Summary
A significant vulnerability exists in the Download Manager by W3 Eden, Inc., characterized by missing authorization. This flaw allows attackers to exploit improperly configured access control security levels, potentially granting unauthorized access to sensitive resources or functionalities. The affected versions range from an unspecified version up to 3.3.03, which emphasizes the need for immediate remedial action for users utilizing this plugin. Ensuring that appropriate security measures are in place is crucial to protect applications from exploitation.
Affected Version(s)
Download Manager <= 3.3.03
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)