4.3

CVE-2014-3849

Exploit

iMember360 3.8.012 - 3.9.001 - Missing Authorization

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.
Mögliche Gegenmaßnahme
iMember360is: Update to version 3.9.001, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imember360Imember360 Version3.8.012 SwPlatformwordpress
Imember360Imember360 Version3.8.013 SwPlatformwordpress
Imember360Imember360 Version3.8.014 SwPlatformwordpress
Imember360Imember360 Version3.9.000 SwPlatformwordpress
Imember360Imember360 Version3.9.001 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt iMember360is
Version [3.8.012, 3.9.001)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.97% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.html
Exploit
http://seclists.org/fulldisclosure/2014/Apr/265
Exploit
http://www.exploit-db.com/exploits/33076
Exploit
http://www.osvdb.org/106300
https://www.wordfence.com/threat-intel/vulnerabilities/id/5263fa58-18d2-49a2-bc5b-3d3fd3cd1377
Third Party Advisory