Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-355f-hgvp-6hq8

Опубликовано: 12 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged in another attack.

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged in another attack.

EPSS

Процентиль: 56%
0.00334
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-732

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged in another attack.

EPSS

Процентиль: 56%
0.00334
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-732