Cross Site Scripting Vulnerability in CM Download Manager Plugin for WordPress
CVE-2020-24145

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 July 2021

Summary

A Cross Site Scripting (XSS) vulnerability exists in the CM Download Manager plugin for WordPress, specifically in version 2.7.0. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML through a specially crafted deletescreenshot action. When exploited, this flaw can lead to the unauthorized execution of scripts in the context of users accessing the vulnerable application, potentially allowing attackers to manipulate user sessions, redirect users to malicious sites, or perform other malicious actions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.