Show filters
33 Total Results
Displaying 31-33 of 33
Sort by:
Attacker Value
Unknown
CVE-2021-24385
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which invokes this function also does not have any required permissions/authentication and can be accessed by an anonymous user.
0
Attacker Value
Unknown
CVE-2020-24142
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute command on services
0
Attacker Value
Unknown
CVE-2020-24143
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
0