Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3149

Опубликовано: 17 окт. 2022
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wp_custom_cursors_project:wp_custom_cursors:*:*:*:*:*:wordpress:*:*
Версия до 3.0.1 (исключая)

EPSS

Процентиль: 26%
0.00093
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

EPSS

Процентиль: 26%
0.00093
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79