Логотип exploitDog
bind:CVE-2021-24823
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24823

Количество 2

Количество 2

nvd логотип

CVE-2021-24823

почти 4 года назад

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-v252-c336-2rvr

почти 4 года назад

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24823

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-v252-c336-2rvr

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

0%
Низкий
почти 4 года назад

Уязвимостей на страницу