Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11396

Опубликовано: 14 янв. 2025
Источник: nvd
CVSS3: 5.3
EPSS Средний

Описание

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:awplife:event_monster:*:*:*:*:*:wordpress:*:*
Версия до 1.4.4 (исключая)

EPSS

Процентиль: 98%
0.47484
Средний

5.3 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 5.3
github
около 1 года назад

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

EPSS

Процентиль: 98%
0.47484
Средний

5.3 Medium

CVSS3

Дефекты

CWE-359