4.3
CVE-2021-24688
- EPSS 0.43%
- Veröffentlicht 28.02.2022 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:53:34
- CVE-Watchlists
- Unerledigt
Orange Form <= 1.0.1 - Unauthenticated Arbitrary Post Deletion
Orange Form <= 1.0.1 - Cross-Site Request Forgery
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The AJAX calls performing actions on posts also do not ensure that the post belong to them (or that they are allowed to perform such action on it)
Mögliche Gegenmaßnahme
Orange Form: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Orange-form Project ≫ Orange-form SwPlatformwordpress Version <= 1.0.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Orange Form
Version
*-1.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.351 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://wpscan.com/vulnerability/78bc7cf1-7563-4ada-aec9-af4c943e3e2c
https://www.wordfence.com/threat-intel/vulnerabilities/id/ab248283-e331-4159-9fe4-249243772c9b