Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c5f-qpcm-fgcv

Опубликовано: 27 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.

EPSS

Процентиль: 31%
0.00116
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.

EPSS

Процентиль: 31%
0.00116
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639