6.5

CVE-2021-25097

LabTools <= 1.0 - Subscriber+ Arbitrary Publication Deletion

LabTools <= 1.0 - Missing Authorization

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
Mögliche Gegenmaßnahme
LabTools: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CreativityjuiceLabtools SwPlatformwordpress Version <= 1.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt LabTools
Version *-1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.299
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://wpscan.com/vulnerability/67f5beb8-2cb0-4b43-87c7-dead9c005f9c
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/ab9d3fa4-f2b1-4f38-b928-a1220cfeca75
Third Party Advisory