Tipsandtricks-hq
Tipsandtricks-hq Simple Download Monitor: vulnerabilidades y CVE
Tipsandtricks-hq Simple Download Monitor tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-24692 | Media (6.5) | 1.4% | — | 14 mar 2022 | The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. |
| CVE-2021-24696 | Alta (8.8) | 0.63% | — | 24 ene 2022 | The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure… |
| CVE-2021-24694 | Media (5.4) | 0.61% | — | 24 ene 2022 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download… |
| CVE-2021-24698 | Media (4.3) | 0.68% | — | 8 nov 2021 | The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. |
| CVE-2021-24697 | Media (6.1) | 0.83% | — | 8 nov 2021 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes,… |
| CVE-2021-24695 | Alta (7.5) | 1.7% | — | 8 nov 2021 | The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the… |
| CVE-2021-24693 | Crítica (9) | 1.3% | — | 8 nov 2021 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored… |
| CVE-2020-5651 | Alta (8.8) | 1.5% | — | 21 oct 2020 | SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL. |
| CVE-2020-5650 | Media (6.1) | 0.94% | — | 21 oct 2020 | Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. |
Otros productos de Tipsandtricks-hq
WP Affiliate Platform · 11ALL IN ONE WP Security & Firewall · 11WP Emember · 11WP Estore · 8Wordpress Simple Paypal Shopping Cart · 7Compact WP Audio Player · 6WP Video Lightbox · 4WP Express Checkout · 4Software License Manager · 3Category Specific RSS Feed Subscription · 3Accept Stripe · 1Simple Photo Gallery · 1