Vulnerabilities > CVE-2021-24695 - Unspecified vulnerability in Tipsandtricks-Hq Simple Download Monitor

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tipsandtricks-hq

Summary

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

Vulnerable Configurations

Part Description Count
Application
Tipsandtricks-Hq
98