Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rw4-5qwp-72w6

Опубликовано: 15 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

EPSS

Процентиль: 55%
0.00321
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

EPSS

Процентиль: 55%
0.00321
Низкий

7.5 High

CVSS3

Дефекты

CWE-200