Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v252-c336-2rvr

Опубликовано: 01 мар. 2022
Источник: github
Github: Не прошло ревью

Описание

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

EPSS

Процентиль: 38%
0.00165
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

EPSS

Процентиль: 38%
0.00165
Низкий

Дефекты

CWE-352