Логотип exploitDog
bind:CVE-2022-4107
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4107

Количество 2

Количество 2

nvd логотип

CVE-2022-4107

около 3 лет назад

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2f42-3cfg-m57p

около 3 лет назад

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-4107

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2f42-3cfg-m57p

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

CVSS3: 6.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу