Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4426

Опубликовано: 09 янв. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpswings:mautic_integration_for_woocommerce:*:*:*:*:*:wordpress:*:*
Версия до 1.0.3 (исключая)

EPSS

Процентиль: 40%
0.00185
Низкий

4.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.3
github
около 3 лет назад

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

EPSS

Процентиль: 40%
0.00185
Низкий

4.3 Medium

CVSS3

Дефекты