Логотип exploitDog
bind:CVE-2022-4426
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4426

Количество 2

Количество 2

nvd логотип

CVE-2022-4426

около 3 лет назад

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c2gf-h728-j378

около 3 лет назад

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-4426

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-c2gf-h728-j378

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу