Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fvv-qqh5-frx3

Опубликовано: 15 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

EPSS

Процентиль: 77%
0.01069
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

EPSS

Процентиль: 77%
0.01069
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502