Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24jf-3vhr-fw23

Опубликовано: 05 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

EPSS

Процентиль: 73%
0.00785
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

EPSS

Процентиль: 73%
0.00785
Низкий

7.5 High

CVSS3

Дефекты

CWE-200