Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grcr-h33x-c92x

Опубликовано: 14 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

EPSS

Процентиль: 29%
0.00105
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.

EPSS

Процентиль: 29%
0.00105
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352