Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cx33-wwv9-rm3j

Опубликовано: 28 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change or delete arbitrary css and js files.

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change or delete arbitrary css and js files.

EPSS

Процентиль: 38%
0.00168
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
11 месяцев назад

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change or delete arbitrary css and js files.

EPSS

Процентиль: 38%
0.00168
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862