PT-2014-6070 · WordPress · Simple Share Buttons Adder

Duncan Stuart

·

Publicado

2014-07-03

·

Atualizado

2022-11-15

·

CVE-2014-4717

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Share Buttons Adder plugin versions prior to 4.5
Description The issue allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks. This is possible via the ssba share text parameter in a save action to "wp-admin/options-general.php", which is not properly handled in the homepage. Additionally, there are unspecified vectors related to Pages, Posts, Category/Archive pages, or post Excerpts.
Recommendations For versions prior to 4.5, update to version 4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "wp-admin/options-general.php" endpoint and avoiding the use of the ssba share text parameter in save actions until a patch is available.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-4717

Produtos afetados

Simple Share Buttons Adder