PT-2021-16099 · WordPress · Timetable/Event Schedule
Dc11
·
Published
2021-09-20
·
Updated
2022-10-25
·
CVE-2021-24583
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Timetable and Event Schedule WordPress plugin versions prior to 2.4.2
Description
The issue concerns a lack of proper access control and the absence of a CSRF check, allowing any user with the
edit posts capability to delete arbitrary timeslots from any events. This can be exploited via CSRF against a logged-in user with such capability.Recommendations
For versions prior to 2.4.2, update to version 2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the
edit posts capability to trusted users only until the update can be applied.Exploit
Fix
Improper Access Control
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Timetable/Event Schedule