PT-2020-20706 · Idx Broker · Impress For Idx Broker

Published

2020-04-07

·

Updated

2021-07-21

·

CVE-2020-9514

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IMPress for IDX Broker plugin versions prior to 2.6.2
Description An issue was discovered that allows a logged-in user with the Subscriber role to permanently delete arbitrary posts and pages, create new posts with arbitrary subjects, and modify the subjects of existing posts and pages via the create dynamic page and delete dynamic page functions in wrappers.php.
Recommendations For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting the Subscriber role's capabilities to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9514

Affected Products

Impress For Idx Broker