Описание
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.3.1 (исключая)
cpe:2.3:a:ayecode:userswp:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 37%
0.00153
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639
CWE-639
Связанные уязвимости
CVSS3: 4.3
github
почти 4 года назад
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
EPSS
Процентиль: 37%
0.00153
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639
CWE-639