5.3

CVE-2020-14205

Exploit

DiveBook <= 1.1.4 - Improper Access Control

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
Mögliche Gegenmaßnahme
DiveBook: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Divebook ProjectDivebook Version1.1.4 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt DiveBook
Version *-1.1.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.14% 0.624
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://wordpress.org/plugins/divebook/#developers
Vendor Advisory
Release Notes
https://www.hooperlabs.xyz/disclosures/divebook.php
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ebb76379-0cac-47c6-a0eb-34780bc837bc
Third Party Advisory