PT-2019-5819 · WordPress · Arprice Lite

Publicado

2019-08-08

·

Atualizado

2019-08-19

·

CVE-2019-14679

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions ARPrice Lite plugin version 2.2 for WordPress
Description The issue is related to insufficient protection against CSRF requests in the ARPrice Lite plugin for WordPress. This can allow a remote attacker to perform a CSRF attack. The specific endpoint affected is "wp-admin/admin.php?page=arplite import export".
Recommendations For ARPrice Lite plugin version 2.2, consider implementing proper CSRF protection mechanisms to prevent exploitation. As a temporary workaround, restrict access to the "wp-admin/admin.php?page=arplite import export" endpoint to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-03109
CVE-2019-14679

Produtos afetados

Arprice Lite