Vulnerabilities > CVE-2023-3814 - Incorrect Authorization vulnerability in Advancedfilemanager Advanced File Manager

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
advancedfilemanager
CWE-863

Summary

The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

Vulnerable Configurations

Part Description Count
Application
Advancedfilemanager
54

Common Weakness Enumeration (CWE)