2024-12-15 03:03:56 +00:00

115 lines
3.5 KiB
JSON

{
"id": "CVE-2021-25002",
"sourceIdentifier": "contact@wpscan.com",
"published": "2022-05-02T16:15:07.973",
"lastModified": "2024-11-21T05:54:09.977",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL"
},
{
"lang": "es",
"value": "El plugin Tipsacarrier WordPress antes de la versi\u00f3n 1.5.0.5 no tiene ninguna comprobaci\u00f3n de autorizaci\u00f3n en algunas funciones, lo que podr\u00eda permitir a los usuarios no autentificados acceder a los datos de los pedidos que podr\u00edan ser utilizados para recuperar la direcci\u00f3n completa del cliente, el nombre y el tel\u00e9fono a trav\u00e9s de la URL de seguimiento"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "contact@wpscan.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tipsacarrier_project:tipsacarrier:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "1.5.0.5",
"matchCriteriaId": "38534773-F506-4CF8-9777-EF55B78E26BB"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7c",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7c",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}