Логотип exploitDog
bind:CVE-2023-3720
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-3720

Количество 2

Количество 2

nvd логотип

CVE-2023-3720

больше 2 лет назад

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v9xx-v54p-m2hw

больше 2 лет назад

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-3720

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-v9xx-v54p-m2hw

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу