Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown
CVE-2021-24693
Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin
0
Attacker Value
Unknown
CVE-2021-24695
Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
0
Attacker Value
Unknown
CVE-2021-31567
Disclosure Date: October 29, 2021 (last updated October 07, 2023)
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
0
Attacker Value
Unknown
CVE-2021-23174
Disclosure Date: October 29, 2021 (last updated September 17, 2024)
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
0
Attacker Value
Unknown
CVE-2020-5651
Disclosure Date: October 21, 2020 (last updated November 28, 2024)
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
0
Attacker Value
Unknown
CVE-2020-5650
Disclosure Date: October 21, 2020 (last updated November 28, 2024)
Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-9296
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
0
Attacker Value
Unknown
CVE-2018-5212
Disclosure Date: January 04, 2018 (last updated November 26, 2024)
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
0
Attacker Value
Unknown
CVE-2018-5213
Disclosure Date: January 04, 2018 (last updated November 26, 2024)
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
0
Attacker Value
Unknown
CVE-2012-4768
Disclosure Date: September 04, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
0