Simple Download Monitor <= 3.9.8 - Multiple Cross-Site Request Forgery vulnerabilities

2021-12-21 00:00
apple502j

Strategic Overview

Status
Patched in 3.9.9
Affected Version<= 3.9.8
CVSS8.8High
CVECVE-2021-24696
View all Simple Download Monitor vulnerabilities

Vulnerability Overview

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

Technical Analysis

REMEDIATION: Update to version 3.9.9, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C