6.5
CVE-2023-1093
- EPSS 0.33%
- Veröffentlicht 27.03.2023 16:15:09
- Zuletzt bearbeitet 19.02.2025 21:15:12
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
OAuth Single Sign On - SSO (OAuth Client) < 6.24.2 - IdP Discard via CSRF
OAuth Single Sign On – SSO (OAuth Client) <= 6.24.1- Cross-Site Request Forgery via 'discard' in mooauth_client_applist_page
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
Mögliche Gegenmaßnahme
OAuth Single Sign On – SSO (OAuth Client): Update to version 6.24.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Miniorange ≫ Oauth Single Sign On SwPlatformwordpress Version < 6.24.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
OAuth Single Sign On – SSO (OAuth Client)
Version
*-6.24.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.241 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
https://wpscan.com/vulnerability/1e13b9ea-a3ef-483b-b967-6ec14bd6d54d
https://www.wordfence.com/threat-intel/vulnerabilities/id/a250f678-1ec7-48ea-8b81-e5ef89992155