2024-12-15 03:03:56 +00:00

90 lines
2.6 KiB
JSON

{
"id": "CVE-2022-2877",
"sourceIdentifier": "contact@wpscan.com",
"published": "2022-09-16T09:15:11.137",
"lastModified": "2024-11-21T07:01:51.383",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers."
},
{
"lang": "es",
"value": "El plugin Titan Anti-spam & Security de WordPress versiones anteriores a 7.3.1 no comprueba apropiadamente los encabezados HTTP para comprobar la direcci\u00f3n IP de origen, lo que permite a actores de amenazas omitir su funci\u00f3n de bloqueo al falsificando los encabezados"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "contact@wpscan.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cm-wp:titan_anti-spam_\\&_security:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "7.3.1",
"matchCriteriaId": "69D408EB-20B0-4255-A947-FA6635E6ED3F"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/f1af4267-3a43-4b88-a8b9-c1d5b2aa9d68",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://wpscan.com/vulnerability/f1af4267-3a43-4b88-a8b9-c1d5b2aa9d68",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}