PT-2022-20029 · WordPress · Simple Bitcoin Faucets
Lana Codes
·
Published
2022-09-26
·
Updated
2022-12-09
·
CVE-2022-3024
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Simple Bitcoin Faucets WordPress plugin versions 1.7.0 and earlier
Description
The issue is related to the lack of authorisation and CSRF in an AJAX action, allowing any authenticated users to call it and add/delete/edit Bonds. This could also lead to Stored Cross-Site Scripting issues due to the lack of sanitisation and escaping.
Recommendations
For versions 1.7.0 and earlier, update to a version that includes proper authorisation and CSRF protection in AJAX actions, and ensure that user input is properly sanitised and escaped to prevent Stored Cross-Site Scripting issues.
As a temporary workaround, consider restricting access to the AJAX action to prevent exploitation until a patch is available.
Exploit
Fix
Incorrect Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Bitcoin Faucets