Логотип exploitDog
bind:CVE-2019-25060
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-25060

Количество 2

Количество 2

nvd логотип

CVE-2019-25060

почти 4 года назад

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w3xg-7q6m-3xwp

больше 3 лет назад

Improper Access Control in wp-graphql

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-25060

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-w3xg-7q6m-3xwp

Improper Access Control in wp-graphql

CVSS3: 5.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу