Логотип exploitDog
bind:CVE-2021-24806
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24806

Количество 2

Количество 2

nvd логотип

CVE-2021-24806

больше 4 лет назад

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q4r2-83hh-f65v

больше 3 лет назад

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24806

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-q4r2-83hh-f65v

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу