CVE-2021-24695Forced Browsing in Simple Download Monitor

Severity
7.5HIGHNVD
EPSS
1.3%
top 19.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 8
Latest updateMay 24

Description

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-vh6h-77mp-jg82: The Simple Download Monitor WordPress plugin before 32022-05-24
CVEList
Simple Download Monitor < 3.9.6 - Unauthenticated Log Access2021-11-08
CVE-2021-24695 — Forced Browsing | cvebase