Логотип exploitDog
bind:CVE-2023-4245
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4245

Количество 2

Количество 2

nvd логотип

CVE-2023-4245

больше 2 лет назад

The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9g4w-r84w-x2jw

больше 2 лет назад

The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4245

The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-9g4w-r84w-x2jw

The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу