Логотип exploitDog
bind:CVE-2023-1597
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-1597

Количество 2

Количество 2

nvd логотип

CVE-2023-1597

больше 2 лет назад

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32v6-f8xf-f75q

больше 2 лет назад

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-1597

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32v6-f8xf-f75q

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу