2024-12-08 03:06:42 +00:00

52 lines
1.9 KiB
JSON

{
"id": "CVE-2024-6490",
"sourceIdentifier": "contact@wpscan.com",
"published": "2024-07-26T06:15:02.927",
"lastModified": "2024-11-21T09:49:44.290",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10."
},
{
"lang": "es",
"value": "Durante las pruebas del complemento Master Slider de WordPress hasta la versi\u00f3n 3.9.10, se encontr\u00f3 una vulnerabilidad CSRF, que permite a un usuario no autorizado manipular solicitudes en nombre de la v\u00edctima y, por lo tanto, eliminar todos los sliders dentro del complemento Master Slider de WordPress hasta la versi\u00f3n 3.9.10."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"references": [
{
"url": "https://wpscan.com/vulnerability/5a56e5aa-841d-4be5-84da-4c3b7602f053/",
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/5a56e5aa-841d-4be5-84da-4c3b7602f053/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}