Описание
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.1 (включая)
cpe:2.3:a:user_activity_project:user_activity:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 34%
0.00136
Низкий
7.5 High
CVSS3
Дефекты
CWE-290
Связанные уязвимости
CVSS3: 7.5
github
почти 3 года назад
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
EPSS
Процентиль: 34%
0.00136
Низкий
7.5 High
CVSS3
Дефекты
CWE-290