Описание
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.5 (исключая)
cpe:2.3:a:student_result_or_employee_database_project:student_result_or_employee_database:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 23%
0.00079
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-352
CWE-352
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting
EPSS
Процентиль: 23%
0.00079
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-352
CWE-352