Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c75r-2gqr-7xhr

Опубликовано: 27 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

EPSS

Процентиль: 51%
0.00276
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

EPSS

Процентиль: 51%
0.00276
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200