Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cv2-662c-vm87

Опубликовано: 16 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

EPSS

Процентиль: 64%
0.00474
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

EPSS

Процентиль: 64%
0.00474
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862