Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhcf-w95r-xjvr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack

The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack

EPSS

Процентиль: 34%
0.0014
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack

EPSS

Процентиль: 34%
0.0014
Низкий

Дефекты

CWE-352