Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38345

Опубликовано: 14 окт. 2021
Источник: nvd
CVSS3: 7.1
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was found by another researcher in Brizy <= 1.0.125 and fixed in version 1.0.126, but the vulnerability was reintroduced in version 1.0.127.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:brizy:brizy-page_builder:*:*:*:*:wordpress:*:*:*
Версия до 1.0.1.126 (исключая)
cpe:2.3:a:brizy:brizy-page_builder:*:*:*:*:*:*:*:*
Версия от 1.0.127 (включая) до 2.3.11 (включая)

EPSS

Процентиль: 48%
0.00253
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79
CWE-863

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was found by another researcher in Brizy <= 1.0.125 and fixed in version 1.0.126, but the vulnerability was reintroduced in version 1.0.127.

EPSS

Процентиль: 48%
0.00253
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79
CWE-863