Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mcw-g4r6-c9vv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

EPSS

Процентиль: 38%
0.00168
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

EPSS

Процентиль: 38%
0.00168
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862