Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2897

Опубликовано: 09 июн. 2023
Источник: nvd
CVSS3: 3.7
CVSS3: 5.3
EPSS Низкий

Описание

The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose of validating allowed IP addresses against a Maintenance Mode whitelist. Supplying a whitelisted IP address within the 'X-Forwarded-For' header allows maintenance mode to be bypassed and may result in the disclosure of potentially sensitive information or allow access to restricted functionality.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:brizy:brizy:*:*:*:*:*:wordpress:*:*
Версия до 2.4.18 (включая)

EPSS

Процентиль: 16%
0.0005
Низкий

3.7 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 3.7
github
больше 2 лет назад

The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose of validating allowed IP addresses against a Maintenance Mode whitelist. Supplying a whitelisted IP address within the 'X-Forwarded-For' header allows maintenance mode to be bypassed and may result in the disclosure of potentially sensitive information or allow access to restricted functionality.

EPSS

Процентиль: 16%
0.0005
Низкий

3.7 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-345