cvelist/2022/3xxx/CVE-2022-3097.json

75 lines
2.2 KiB
JSON
Raw Normal View History

2022-09-02 13:00:37 +00:00
{
2022-11-29 14:00:36 +00:00
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2022-3097",
"ASSIGNER": "contact@wpscan.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
2022-10-24 16:09:14 +02:00
{
2022-11-29 14:00:36 +00:00
"lang": "eng",
"value": "CWE-352 Cross-Site Request Forgery (CSRF)"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Unknown",
"product": {
"product_data": [
{
"product_name": "Plugin LBstopattack",
"version": {
"version_data": [
{
"version_value": "0",
"version_affected": "="
}
]
}
}
]
2022-10-24 16:09:14 +02:00
}
}
]
}
2022-11-29 14:00:36 +00:00
},
"references": {
"reference_data": [
{
"url": "https://wpscan.com/vulnerability/9ebb8318-ebaf-4de7-b337-c91327685a43",
"refsource": "MISC",
"name": "https://wpscan.com/vulnerability/9ebb8318-ebaf-4de7-b337-c91327685a43"
}
2022-09-02 13:00:37 +00:00
]
2022-11-29 14:00:36 +00:00
},
"generator": {
"engine": "WPScan CVE Generator"
},
"source": {
"discovery": "EXTERNAL"
},
"credits": [
{
"lang": "en",
"value": "Daniel Ruf"
}
2022-10-24 16:09:14 +02:00
]
2022-09-02 13:00:37 +00:00
}