Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13772

Опубликовано: 14 мар. 2025
Источник: nvd
CVSS3: 5.6
CVSS3: 5.9
EPSS Низкий

Описание

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uxper:civi:*:*:*:*:*:wordpress:*:*
Версия до 2.1.4 (включая)

EPSS

Процентиль: 26%
0.0009
Низкий

5.6 Medium

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 5.6
github
11 месяцев назад

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.

EPSS

Процентиль: 26%
0.0009
Низкий

5.6 Medium

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-288
CWE-306