PT-2021-16335 · WordPress · Qr Redirector
Apple502J
·
Published
2021-11-17
·
Updated
2021-11-19
·
CVE-2021-24853
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
QR Redirector WordPress plugin versions prior to 1.6
Description:
The issue concerns a lack of capability and CSRF checks when saving bulk QR Redirector settings via the "qr save bulk" AJAX action. This could allow any authenticated user, such as a subscriber, to change the redirect response status code of arbitrary QR Redirects.
Recommendations:
For versions prior to 1.6, update to version 1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "qr save bulk" AJAX action to prevent unauthorized changes to QR Redirect settings.
Exploit
Fix
Improper Access Control
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qr Redirector