Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmfh-pxqg-pgf4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.

Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.

EPSS

Процентиль: 29%
0.00103
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.

EPSS

Процентиль: 29%
0.00103
Низкий

Дефекты

CWE-352