Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6x7-qg62-r396

Опубликовано: 07 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

EPSS

Процентиль: 23%
0.00078
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

EPSS

Процентиль: 23%
0.00078
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352