Описание
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
EPSS
Процентиль: 26%
0.00326
Низкий
7.5 High
CVSS3
Дефекты
CWE-269
Связанные уязвимости
CVSS3: 7.5
github
около 1 месяца назад
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
EPSS
Процентиль: 26%
0.00326
Низкий
7.5 High
CVSS3
Дефекты
CWE-269