Логотип exploitDog
bind:CVE-2022-3119
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3119

Количество 2

Количество 2

nvd логотип

CVE-2022-3119

больше 3 лет назад

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wh77-xq95-gvgr

больше 3 лет назад

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3119

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-wh77-xq95-gvgr

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу