7.5

CVE-2021-24146

Exploit

Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export

Modern Events Calendar Lite <= 5.16.4 - Unauthenticated Events Export

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.
Mögliche Gegenmaßnahme
Modern Events Calendar Lite: Update to version 5.16.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WebnusModern Events Calendar Lite SwPlatformwordpress Version < 5.16.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Modern Events Calendar Lite
Version *-5.16.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 31.04% 0.98
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://packetstormsecurity.com/files/163345/WordPress-Modern-Events-Calendar-5.16.2-Information-Disclosure.html
Third Party Advisory
Exploit
VDB Entry
https://wpscan.com/vulnerability/c7b1ebd6-3050-4725-9c87-0ea525f8fecc
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/8e361473-8ed6-41d0-b409-2436189c1120
Third Party Advisory