Vulnerabilities > CVE-2021-24692 - Unspecified vulnerability in Tipsandtricks-Hq Simple Download Monitor

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tipsandtricks-hq

Summary

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

Vulnerable Configurations

Part Description Count
Application
Tipsandtricks-Hq
98