PT-2019-12827 · WordPress · Wp Live Chat Support
Publicado
2019-06-11
·
Atualizado
2021-08-12
·
CVE-2019-12498
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Live Chat Support plugin versions prior to 8.0.33
Description
The issue allows unauthorized remote attackers to steal chat logs and manipulate sessions due to certain REST API calls being accepted without invoking the
wplc api permission check protection mechanism. Over 50,000 businesses are potentially affected.Recommendations
For versions prior to 8.0.33, update to version 8.0.33 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoints until the update is applied.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Live Chat Support