Cross Site Scripting Vulnerability in CM Download Manager Plugin for WordPress
CVE-2020-24145
6.1MEDIUM
Summary
A Cross Site Scripting (XSS) vulnerability exists in the CM Download Manager plugin for WordPress, specifically in version 2.7.0. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML through a specially crafted deletescreenshot action. When exploited, this flaw can lead to the unauthorized execution of scripts in the context of users accessing the vulnerable application, potentially allowing attackers to manipulate user sessions, redirect users to malicious sites, or perform other malicious actions.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved