Описание
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.1 (исключая)
cpe:2.3:a:custom_popup_builder_project:custom_popup_builder:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 83%
0.01993
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1284
Связанные уязвимости
CVSS3: 7.5
github
почти 4 года назад
The Popup | Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
EPSS
Процентиль: 83%
0.01993
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1284