Логотип exploitDog
bind:CVE-2021-25087
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25087

Количество 2

Количество 2

nvd логотип

CVE-2021-25087

почти 4 года назад

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hc7r-q2m2-f836

почти 4 года назад

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-25087

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-hc7r-q2m2-f836

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

CVSS3: 7.5
2%
Низкий
почти 4 года назад

Уязвимостей на страницу