Логотип exploitDog
bind:CVE-2022-3894
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3894

Количество 2

Количество 2

nvd логотип

CVE-2022-3894

почти 3 года назад

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r88p-4gjh-7prw

почти 3 года назад

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3894

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-r88p-4gjh-7prw

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.

CVSS3: 4.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу