2024-07-14 02:06:08 +00:00

86 lines
2.4 KiB
JSON

{
"id": "CVE-2022-3082",
"sourceIdentifier": "contact@wpscan.com",
"published": "2022-10-17T12:15:10.040",
"lastModified": "2023-11-07T03:50:45.627",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example"
},
{
"lang": "es",
"value": "El plugin miniOrange Discord Integration de WordPress versiones anteriores a 2.1.6, no presenta autorizaci\u00f3n y de tipo CSRF en algunas de sus acciones AJAX, lo que permite a cualquier usuario con sesi\u00f3n iniciada, como el suscriptor, llamar y deshabilitar la aplicaci\u00f3n, por ejemplo"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
},
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:miniorange:discord_integration:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "2.1.6",
"matchCriteriaId": "560B494A-2779-4C45-971B-125676082319"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/a91d0501-c2a9-4c6c-b5da-b3fc29442a4f",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}