Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gg89-hw93-j4hc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

EPSS

Процентиль: 30%
0.00112
Низкий

Дефекты

CWE-284
CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

EPSS

Процентиль: 30%
0.00112
Низкий

Дефекты

CWE-284
CWE-352