Vulnerabilities > CVE-2022-2367 - Authorization Bypass Through User-Controlled Key vulnerability in WSM Downloader Project WSM Downloader 1.4.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
wsm-downloader-project
CWE-639

Summary

The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation

Vulnerable Configurations

Part Description Count
Application
Wsm_Downloader_Project
1