Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf96-763w-mh5v

Опубликовано: 25 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

EPSS

Процентиль: 89%
0.04398
Низкий

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

EPSS

Процентиль: 89%
0.04398
Низкий

Дефекты

CWE-601