Record summary

CVE-2022-1119 has a selected CVSS score of 7.5 (high); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.2.7affected

Proofs of concept

2

Repository PoCs

GitHubW01fh4cker/SereinRepository PoCby W01fh4ckerStars: 1,251Not analyzed57 files

647.5 KiB · linked to 13 vulnerabilities

GitHub

PoC details
GitHubz92g/CVE-2022-1119Repository PoCby z92gStars: 5Not analyzed8 files

41.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Simple File List <3.2.8 - Local File InclusionCVSS 7.5

WordPress Simple File List before 3.2.8 is vulnerable to local file inclusion via the eeFile parameter in the ~/includes/ee-downloader.php due to missing controls which make it possible for unauthenticated attackers retrieve arbitrary files.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to further compromise.

Remediation

Update WordPress Simple File List to version 3.2.8 or later to mitigate the vulnerability.

WeaknessesCWE-22
Authorsrandom-robbie
Template tagscvecve2022wpwp-pluginwpscanlfiwordpresssimplefilelistvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:simplefilelist:simple-file-list:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

6