Описание
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other user settings.
Ссылки
- Issue Tracking
- Issue Tracking
- Third Party Advisory
- Issue Tracking
- Issue Tracking
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.4.7 (включая)
cpe:2.3:a:squirrly:starbox:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 49%
0.00259
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 4.3
github
около 2 лет назад
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other user settings.
EPSS
Процентиль: 49%
0.00259
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-639