8.8
CVE-2021-24162
- EPSS 0.8%
- Veröffentlicht 05.04.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:52:29
- Erkennungen
Responsive Menu < 4.0.4 - CSRF to Settings Update
Responsive Menu <= 4.0.3 - Cross-Site Request Forgery to Setting Modification
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.
Mögliche Gegenmaßnahme
Responsive Menu – Create Mobile-Friendly Menu: Update to version 4.0.4, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Expresstech ≫ Responsive Menu SwEdition free SwPlatform wordpress Version < 4.0.4
Expresstech ≫ Responsive Menu SwEdition pro SwPlatform wordpress Version < 4.0.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Responsive Menu – Create Mobile-Friendly Menu
Version
[*, 4.0.4)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.8% | 0.516 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin/
https://wpscan.com/vulnerability/923fc3a3-4bcc-4b48-870a-6150e14509b5
https://www.wordfence.com/threat-intel/vulnerabilities/id/08ba0f2a-f3eb-4d79-abba-99e64df0fe4b