CVEs Blog | G5 Cyber Security

CVE-2020-24143 – Directory traversal in the Video Downloader for TikTok (aka downloader-ti

Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24143

Reference (s):

Exit mobile version