Vulnerabilities (CVE)

Filtered by vendor Ninjateam Subscribe
Filtered by product Video Downloader For Tiktok
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24142 1 Ninjateam 1 Video Downloader For Tiktok 2024-02-28 7.5 HIGH 9.8 CRITICAL
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute command on services
CVE-2020-24143 1 Ninjateam 1 Video Downloader For Tiktok 2024-02-28 5.0 MEDIUM 7.5 HIGH
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.