CVE-2021-24692
- EPSS 0.74%
- Veröffentlicht 14.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:34
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
CVE-2021-24694
- EPSS 0.18%
- Veröffentlicht 24.01.2022 08:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:34
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder"...
CVE-2021-24696
- EPSS 0.11%
- Veröffentlicht 24.01.2022 08:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:35
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete ...
- EPSS 0.62%
- Veröffentlicht 08.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:34
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Giv...
CVE-2021-24695
- EPSS 1.34%
- Veröffentlicht 08.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:34
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Informa...
CVE-2021-24697
- EPSS 0.21%
- Veröffentlicht 08.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:35
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Sc...
CVE-2021-24698
- EPSS 0.14%
- Veröffentlicht 08.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:35
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
CVE-2020-5651
- EPSS 0.75%
- Veröffentlicht 21.10.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:34:25
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
CVE-2020-5650
- EPSS 0.28%
- Veröffentlicht 21.10.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:34:25
Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.