Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgc8-hcph-rwrm

Опубликовано: 16 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

EPSS

Процентиль: 72%
0.00727
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

EPSS

Процентиль: 72%
0.00727
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79