Логотип exploitDog
bind:CVE-2024-3823
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-3823

Количество 2

Количество 2

nvd логотип

CVE-2024-3823

больше 1 года назад

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-7gh2-59h4-gcm3

больше 1 года назад

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 2.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-3823

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-7gh2-59h4-gcm3

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 2.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу