CVE Feed

    Dashboard / CVE / CVE-2020-24312

    CVE-2020-24312

    mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.

    Published:Aug 26, 2020
    Last Modified:Mar 24, 2025
    EPS:Aug 26, 2020
    EPSS Score:0.45545
    CVSS Score:7.5

    Affected Products

    Vendor
    Filemanagerpro
    Product
    File Manager

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High