Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10568

Опубликовано: 14 мар. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:onthegosystems:sitepress-multilingual-cms:*:*:*:*:*:wordpress:*:*
Версия до 4.3.7 (исключая)
cpe:2.3:a:onthegosystems:sitepress-multilingual-cms:4.3.7:b.1:*:*:*:wordpress:*:*

EPSS

Процентиль: 84%
0.02264
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
больше 3 лет назад

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

EPSS

Процентиль: 84%
0.02264
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352