Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown

CVE-2023-31219

Disclosure Date: November 13, 2023 (last updated November 18, 2023)
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
Attacker Value
Unknown

CVE-2022-2981

Disclosure Date: October 10, 2022 (last updated October 08, 2023)
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Attacker Value
Unknown

CVE-2022-2222

Disclosure Date: July 17, 2022 (last updated October 07, 2023)
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Attacker Value
Unknown

CVE-2021-24692

Disclosure Date: March 14, 2022 (last updated October 07, 2023)
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
Attacker Value
Unknown

CVE-2021-24696

Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
Attacker Value
Unknown

CVE-2021-24694

Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.
Attacker Value
Unknown

CVE-2021-36920

Disclosure Date: January 11, 2022 (last updated October 07, 2023)
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
Attacker Value
Unknown

CVE-2021-24786

Disclosure Date: January 03, 2022 (last updated October 07, 2023)
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Attacker Value
Unknown

CVE-2021-24697

Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-24698

Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.