Описание
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.
Ссылки
- Third Party Advisory
- Exploit
- Third Party Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия от 0.0.1 (включая) до 0.0.5 (исключая)
cpe:2.3:a:getnet_argentina_para_woocommerce_project:getnet_argentina_para_woocommerce:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
7.5 High
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.
EPSS
Процентиль: 25%
0.00085
Низкий
7.5 High
CVSS3