Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8qw-7677-x9rf

Опубликовано: 26 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

EPSS

Процентиль: 72%
0.00732
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

EPSS

Процентиль: 72%
0.00732
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284