Tipsandtricks-hq

Simple Download Monitor

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.74%
  • Veröffentlicht 14.03.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:34

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 24.01.2022 08:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:34

The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder"...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 24.01.2022 08:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:35

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete ...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 08.11.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:34

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Giv...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 08.11.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:34

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Informa...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 08.11.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:35

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Sc...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 08.11.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:35

The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

  • EPSS 0.75%
  • Veröffentlicht 21.10.2020 16:15:15
  • Zuletzt bearbeitet 21.11.2024 05:34:25

SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.

  • EPSS 0.28%
  • Veröffentlicht 21.10.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:34:25

Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.