CVE-2022-3899
The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into submitting a form.
- Affected products
- 3Dprint, Tiny File Manager
- 3dprint Project 3dprint
- < 3.5.6.9
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2024-01-16
CVE-2022-3899 at NVD
1 known exploit for CVE-2022-3899
Proof-of-concept code and exploit modules indexed by Sploitus