2024-12-08 03:06:42 +00:00

76 lines
3.4 KiB
JSON

{
"id": "CVE-2024-3682",
"sourceIdentifier": "security@wordfence.com",
"published": "2024-04-26T10:15:11.693",
"lastModified": "2024-11-21T09:30:10.293",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up to, and including, 3.4.3, and versions up to, and including, 5.4.3, respectively, via the ajaxSendReport function. This makes it possible for unauthenticated attackers to extract sensitive data from a log file, including system information and (in the Pro version) license keys. Successful exploitation requires an administrator to have used the 'Contact Us' functionality along with the \"Enable this option to automatically submit the log files.\" option."
},
{
"lang": "es",
"value": "Los complementos WP STAGING y WP STAGING Pro para WordPress son vulnerables a la exposici\u00f3n de informaci\u00f3n confidencial en versiones hasta la 3.4.3 incluida, y versiones hasta la 5.4.3 incluida, respectivamente, a trav\u00e9s de la funci\u00f3n ajaxSendReport. Esto hace posible que atacantes no autenticados extraigan datos confidenciales de un archivo de registro, incluida informaci\u00f3n del sistema y (en la versi\u00f3n Pro) claves de licencia. La explotaci\u00f3n exitosa requiere que un administrador haya utilizado la funcionalidad \"Cont\u00e1ctenos\" junto con la opci\u00f3n \"Habilite esta opci\u00f3n para enviar autom\u00e1ticamente los archivos de registro\"."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"references": [
{
"url": "https://plugins.trac.wordpress.org/changeset/3076275/wp-staging",
"source": "security@wordfence.com"
},
{
"url": "https://wp-staging.com/wp-staging-changelog/",
"source": "security@wordfence.com"
},
{
"url": "https://wp-staging.com/wp-staging-pro-changelog/",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75eab54b-dbe0-4440-b4ab-601c5041e180?source=cve",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3076275/wp-staging",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wp-staging.com/wp-staging-changelog/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wp-staging.com/wp-staging-pro-changelog/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75eab54b-dbe0-4440-b4ab-601c5041e180?source=cve",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}