Описание
The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.1 (включая)
cpe:2.3:a:armandofiore:fl3r_feelbox:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 31%
0.00116
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
github
около 3 лет назад
The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables
EPSS
Процентиль: 31%
0.00116
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352