Логотип exploitDog
bind:CVE-2021-25117
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25117

Количество 3

Количество 3

nvd логотип

CVE-2021-25117

около 2 лет назад

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-5c46-pxg6-m63r

около 2 лет назад

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

CVSS3: 4.8
EPSS: Низкий
fstec логотип

BDU:2024-00648

около 5 лет назад

Уязвимость плагина PostRatings системы управления содержимым сайта WordPress, позволяющая нарушителю осуществить CSRF-атаку

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-25117

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-5c46-pxg6-m63r

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

CVSS3: 4.8
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-00648

Уязвимость плагина PostRatings системы управления содержимым сайта WordPress, позволяющая нарушителю осуществить CSRF-атаку

CVSS3: 4.8
0%
Низкий
около 5 лет назад

Уязвимостей на страницу