Логотип exploitDog
bind:CVE-2024-4873
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-4873

Количество 2

Количество 2

nvd логотип

CVE-2024-4873

больше 1 года назад

The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to replace images uploaded by higher level users such as admins.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f5hm-5m7c-gmr8

больше 1 года назад

The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to replace images uploaded by higher level users such as admins.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-4873

The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to replace images uploaded by higher level users such as admins.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-f5hm-5m7c-gmr8

The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to replace images uploaded by higher level users such as admins.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу