PT-2014-8984 · Twitter · Post To Twitter Plugin

Publicado

2014-12-31

·

Atualizado

2017-09-08

·

CVE-2014-9393

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Post to Twitter plugin versions 0.7 and earlier
Description The issue allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks. This is achieved via the idptt twitter username or idptt tweet prefix parameter to "wp-admin/options-general.php".
Recommendations For Post to Twitter plugin versions 0.7 and earlier, consider disabling the plugin until a patch is available to prevent potential cross-site request forgery (CSRF) attacks. Restrict access to the "wp-admin/options-general.php" endpoint to minimize the risk of exploitation. Avoid using the idptt twitter username and idptt tweet prefix parameters in the affected endpoint until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9393

Produtos afetados

Post To Twitter Plugin