Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g77v-mcj9-92j3

Опубликовано: 27 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.

EPSS

Процентиль: 40%
0.00187
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.

EPSS

Процентиль: 40%
0.00187
Низкий

5.3 Medium

CVSS3