PT-2014-2766 · Hms · Hms Testimonials

Adéla Goldová

·

Publicado

2014-04-02

·

Atualizado

2020-02-03

·

CVE-2013-4240

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HMS Testimonials plugin versions prior to 2.0.11
Description The issue allows remote attackers to hijack the authentication of administrators for various requests, including adding new testimonials via the "hms-testimonials-addnew" page, adding new groups via the "hms-testimonials-addnewgroup" page, changing default settings via the "hms-testimonials-settings" page, changing advanced settings via the "hms-testimonials-settings-advanced" page, changing custom fields settings via the "hms-testimonials-settings-fields" page, or changing template settings via the "hms-testimonials-templates-new" page to wp-admin/admin.php.
Recommendations Update to version 2.0.11 or later to resolve the issue.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4240

Produtos afetados

Hms Testimonials