Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2gf-h728-j378

Опубликовано: 10 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

EPSS

Процентиль: 40%
0.00185
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

EPSS

Процентиль: 40%
0.00185
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352