Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93c5-xvhq-3947

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

EPSS

Процентиль: 39%
0.00177
Низкий

8.1 High

CVSS3

Дефекты

CWE-352
CWE-862

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

EPSS

Процентиль: 39%
0.00177
Низкий

8.1 High

CVSS3

Дефекты

CWE-352
CWE-862