Описание
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pluck-cms:pluck:4.7.15:-:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00102
Низкий
4.8 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-295
Связанные уязвимости
github
около 4 лет назад
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
EPSS
Процентиль: 28%
0.00102
Низкий
4.8 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-295