Логотип exploitDog
bind:CVE-2021-24500
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24500

Количество 2

Количество 2

nvd логотип

CVE-2021-24500

больше 4 лет назад

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-x298-h85x-h99q

больше 3 лет назад

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24500

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-x298-h85x-h99q

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу