Логотип exploitDog
bind:CVE-2021-25014
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25014

Количество 2

Количество 2

nvd логотип

CVE-2021-25014

почти 4 года назад

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-pm3v-7943-w34p

почти 4 года назад

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-25014

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

CVSS3: 3.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-pm3v-7943-w34p

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу