Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqmw-24v9-r296

Опубликовано: 13 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

EPSS

Процентиль: 49%
0.00257
Низкий

7.1 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.1
nvd
почти 3 года назад

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

EPSS

Процентиль: 49%
0.00257
Низкий

7.1 High

CVSS3

Дефекты

CWE-352