PT-2019-14320 · Articulate · Insert/Embed Articulate Content Into Wordpress
Published
2019-08-27
·
Updated
2020-08-24
·
CVE-2019-15648
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
insert-or-embed-articulate-content-into-wordpress plugin versions prior to 4.29991
Description
The issue is related to insufficient restrictions on deleting or renaming content by a Subscriber.
Recommendations
For versions prior to 4.29991, update to version 4.29991 or later to resolve the issue.
Exploit
Fix
CSRF
Missing Authorization
Improper Authentication
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Insert/Embed Articulate Content Into Wordpress