Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3f9-wfr9-6xw8

Опубликовано: 01 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

EPSS

Процентиль: 36%
0.00149
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 9.6
nvd
почти 4 года назад

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

EPSS

Процентиль: 36%
0.00149
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-352