Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64vf-2ppg-3mgq

Опубликовано: 29 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blog

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blog

EPSS

Процентиль: 35%
0.00144
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-352
CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blog

EPSS

Процентиль: 35%
0.00144
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-352
CWE-862