漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Simple Download Monitor < 3.9.9 - Multiple CSRF
Vulnerability Description
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
WordPress plugin 跨站请求伪造漏洞
Vulnerability Description
WordPress plugin是WordPress开源的一个应用插件。 Wordpress Plugin Simple Download Monitor 中存在跨站请求伪造漏洞,该漏洞源于产品不强制进行nonce 检查。攻击者可通过该漏洞导致日志泄漏、删除日志、删除缩略图等操作。以下产品及版本受到影响:Wordpress Plugin Simple Download Monitor 3.9.9 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A