PT-2018-17298 · WordPress · Email Subscribers & Newsletters

Publicado

2018-01-26

·

Atualizado

2018-02-12

·

CVE-2018-6015

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Email Subscribers & Newsletters plugin versions prior to 3.4.8
Description An issue in the plugin allows an attacker to download a CSV data file containing all subscriber data by sending an HTTP POST request to a specific URI, /api endpoint: /?es=export, with the option: view all subscribers in the request body.
Recommendations For versions prior to 3.4.8, update to version 3.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the /api endpoint: /?es=export endpoint to minimize the risk of exploitation. Avoid using the option: view all subscribers in the affected API endpoint until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6015

Produtos afetados

Email Subscribers & Newsletters