Логотип exploitDog
bind:CVE-2023-6875
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6875

Количество 3

Количество 3

nvd логотип

CVE-2023-6875

около 2 лет назад

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-9cw8-p5p2-35pf

около 2 лет назад

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2024-00631

около 2 лет назад

Уязвимость плагина POST SMTP Mailer системы управления содержимым сайта WordPress, позволяющая нарушителю сбросить ключ API и получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6875

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

CVSS3: 9.8
94%
Критический
около 2 лет назад
github логотип
GHSA-9cw8-p5p2-35pf

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

CVSS3: 9.8
94%
Критический
около 2 лет назад
fstec логотип
BDU:2024-00631

Уязвимость плагина POST SMTP Mailer системы управления содержимым сайта WordPress, позволяющая нарушителю сбросить ключ API и получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
94%
Критический
около 2 лет назад

Уязвимостей на страницу