Логотип exploitDog
bind:CVE-2021-25108
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25108

Количество 2

Количество 2

nvd логотип

CVE-2021-25108

около 4 лет назад

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-r5r8-g427-8mp7

около 4 лет назад

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-25108

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

CVSS3: 7.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-r5r8-g427-8mp7

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу