Логотип exploitDog
bind:CVE-2022-0398
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-0398

Количество 2

Количество 2

nvd логотип

CVE-2022-0398

почти 4 года назад

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mvmq-p5xj-8vj6

почти 4 года назад

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0398

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-mvmq-p5xj-8vj6

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

CVSS3: 5.4
0%
Низкий
почти 4 года назад

Уязвимостей на страницу