Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrw2-pv6m-v2w5

Опубликовано: 14 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.

EPSS

Процентиль: 26%
0.0009
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 5.6
nvd
11 месяцев назад

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.

EPSS

Процентиль: 26%
0.0009
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-288
CWE-306