Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10673

Опубликовано: 03 апр. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 9.3
EPSS Низкий

Описание

A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:*
Версия до 2.0.40 (исключая)

EPSS

Процентиль: 62%
0.00428
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.

EPSS

Процентиль: 62%
0.00428
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-352