2024-12-08 03:06:42 +00:00

52 lines
2.0 KiB
JSON

{
"id": "CVE-2024-5167",
"sourceIdentifier": "contact@wpscan.com",
"published": "2024-07-13T06:15:04.303",
"lastModified": "2024-11-21T09:47:06.823",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack"
},
{
"lang": "es",
"value": "El complemento CM Email Registration Blacklist y Whitelist de WordPress anterior a 1.4.9 no tiene verificaci\u00f3n CSRF al agregar o eliminar un elemento de la lista negra o blanca, lo que podr\u00eda permitir a los atacantes hacer que un administrador que haya iniciado sesi\u00f3n agregue o elimine configuraciones de la lista negra o del men\u00fa de la lista blanca a trav\u00e9s de un ataque CSRF"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2
}
]
},
"references": [
{
"url": "https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a/",
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}