Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9r5-v7qg-53gg

Опубликовано: 05 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

EPSS

Процентиль: 50%
0.00269
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

EPSS

Процентиль: 50%
0.00269
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862
CWE-863