Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-10018

Опубликовано: 16 окт. 2024
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mapplic:mapplic:*:*:*:*:lite:wordpress:*:*
Версия до 1.0 (включая)
cpe:2.3:a:mapplic:mapplic:*:*:*:*:-:wordpress:*:*
Версия до 6.1 (включая)

EPSS

Процентиль: 85%
0.02517
Низкий

8.3 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.3
github
больше 1 года назад

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

EPSS

Процентиль: 85%
0.02517
Низкий

8.3 High

CVSS3

Дефекты

CWE-918