Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25102

Опубликовано: 02 мая 2022
Источник: nvd
CVSS3: 4.7
CVSS2: 2.6
EPSS Низкий

Описание

The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_\&_firewall:*:*:*:*:*:wordpress:*:*
Версия до 4.4.11 (исключая)

EPSS

Процентиль: 43%
0.0021
Низкий

4.7 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
github
почти 4 года назад

The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk

EPSS

Процентиль: 43%
0.0021
Низкий

4.7 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-79