Описание
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
Ссылки
- ExploitMailing ListPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- ExploitMailing ListPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.2 (исключая)
cpe:2.3:a:themegrill:themegrill_demo_importer:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 98%
0.50218
Средний
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-306
Связанные уязвимости
github
больше 3 лет назад
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
EPSS
Процентиль: 98%
0.50218
Средний
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-306