5.3
CVE-2020-14205
- EPSS 0.21%
- Veröffentlicht 08.12.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:02:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
DiveBook <= 1.1.4 - Improper Access Control
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
Mögliche Gegenmaßnahme
DiveBook: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
DiveBook
Version
*-1.1.4
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Divebook Project ≫ Divebook Version1.1.4 SwPlatformwordpress
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.439 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.