Описание
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
Ссылки
- Third Party AdvisoryExploit
- Third Party AdvisoryExploit
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.1 (исключая)
cpe:2.3:a:webgarh:offload_videos:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 8%
0.0003
Низкий
8.1 High
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.1
github
9 месяцев назад
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
EPSS
Процентиль: 8%
0.0003
Низкий
8.1 High
CVSS3
Дефекты
CWE-352