目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-9345 PoC — WordPress plugin File Manager, Code Editor, and Backup by Managefy 路径遍历漏洞

来源
关联漏洞
标题: WordPress plugin File Manager, Code Editor, and Backup by Managefy 路径遍历漏洞 (CVE-2025-9345)
Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin File Manager, Code Editor, and Backup by Managefy 1.4.8及之前版本存在路径遍历漏洞,该漏洞源于路径遍历,可能导致文件操作越界。
Description
CVE-2025-9345
介绍
# Proof of Concept Path Traversal in File Manager, Code Editor, and Backup by Managefy 
**Vulnerability Type:** Path Traversal (Arbitrary File Download)

**Affected Function:** `ajax_downloadfile()` 

**Impact:** Authenticated users with low privilege (Subscriber+) can download arbitrary files from the server, including sensitive configuration files, by exploiting insufficient validation of the `flm_file` parameter.  

**CVSS v3.1 Score:** 6.5 (Medium)   
**Vector:** AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

---
## Description

The `flm_file` parameter from the GET request is concatenated directly with the backup directory path without sufficient sanitization. The current sanitization function `Flmbkp_Form_Helper::sanitizeInput_html()` does not prevent sequences like `../`, allowing an attacker to traverse directories outside of the intended backup folder.

```  modules\filemanager\controllers\backups.php
// modules\filemanager\controllers\backups.php
public function ajax_downloadfile()
    {
        check_ajax_referer('flmbkp_ajax_nonce', 'flmbkp_security');
        @set_time_limit(900);
        $flm_file = (isset($_GET['flm_file'])) ? Flmbkp_Form_Helper::sanitizeInput_html($_GET['flm_file']) : '';
        
        $backup_directory=Flmbkp_Form_Helper::backup_directory();
        $fullpath = $backup_directory.'/'.$flm_file;
        
        header("Content-Length: ".filesize($fullpath));
        header("Content-type: application/octet-stream");
        header("Content-Disposition: attachment; filename=\"".basename($fullpath)."\";");
        readfile($fullpath);
        exit;
    }
```

---
### Steps to Reproduce

1.  **Login into the WordPress system** using Subscriber credentials.
![alt](./img/1.png)
2.  **Navigate to Plugins → File Manager & Backup** page.
![alt](./img/2.png)
3.  **Click the "Backup" button** to create a backup file.
![alt](./img/3.png)
4.  In the **Backup Data** section, click the **download file** option.
![alt](./img/4.png)  
5.  Intercept the download request in **Burp Suite** and modify the `flm_file` parameter to include a path traversal payload to target a sensitive file.  
![alt](./img/5.png)

---
### Impact

Disclosure of sensitive system files.

Exposure of credentials stored in files such as wp-config.php, .env, or application logs.

Facilitates further attacks, including full system compromise.

---
### Recommendation
Use realpath() to resolve the absolute path of the requested file and ensure it is inside the backup directory.

Reject requests containing ../, %00, or other traversal-related sequences before file access.

Enforce strict capability checks (e.g., only manage_options users can download backups).

Sanitize and validate the filename against a whitelist of allowed files.

### Video POC
If you're unable to reproduce the issue exactly as described in the report, please refer to the following video demonstration (PoC) for a clear reproduction scenario:

https://www.youtube.com/watch?v=b9M0nMDpMi0
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →