6.5
CVE-2022-1967
- EPSS 0.1%
- Veröffentlicht 04.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:51
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
wp-championship <= 9.2 - Multiple Cross-Site Request Forgery Vulnerabilities
The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
Mögliche Gegenmaßnahme
wp-championship: Update to version 9.3, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
wp-championship
Version
*-9.2
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wp-championship Project ≫ Wp-championship SwPlatformwordpress Version < 9.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.287 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.