Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24226

Опубликовано: 12 апр. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:accessally:accessally:*:*:*:*:*:wordpress:*:*
Версия до 3.5.7 (исключая)

EPSS

Процентиль: 96%
0.25403
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

EPSS

Процентиль: 96%
0.25403
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200