Логотип exploitDog
bind:CVE-2022-0424
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-0424

Количество 2

Количество 2

nvd логотип

CVE-2022-0424

почти 4 года назад

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-28vh-fggg-795m

почти 4 года назад

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0424

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

CVSS3: 5.3
42%
Средний
почти 4 года назад
github логотип
GHSA-28vh-fggg-795m

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

CVSS3: 5.3
42%
Средний
почти 4 года назад

Уязвимостей на страницу