Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hc7r-q2m2-f836

Опубликовано: 08 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

EPSS

Процентиль: 81%
0.01573
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

EPSS

Процентиль: 81%
0.01573
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-862