5.4
CVE-2023-3510
- EPSS 0.14%
- Veröffentlicht 11.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:17:25
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
FTP Access <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the settings of the plugin. The attack could also be perform via CSRF against any authenticated user.
Mögliche Gegenmaßnahme
FTP Access: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
FTP Access
Version
*-1.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Danialhatami ≫ Ftp Access SwPlatformwordpress Version <= 1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.34 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|