PT-2023-11863 · Activello+1 · Activello+2

Jerome Bruandet

·

Published

2023-06-07

·

Updated

2023-06-16

·

CVE-2020-36721

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Brilliance versions prior to 1.2.8 Activello versions prior to 1.4.1 Newspaper X versions prior to 1.3.2
Description The issue is related to the lack of capability and security checks/nonces in the activello activate plugin and activello deactivate plugin functions, located in the inc/welcome-screen/class-activello-welcome.php file. This allows unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Recommendations For The Brilliance version 1.2.7 and earlier, update to version 1.2.8 or later. For Activello version 1.4.0 and earlier, update to version 1.4.1 or later. For Newspaper X version 1.3.1 and earlier, update to version 1.3.2 or later.

Exploit

Fix

Missing Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2020-36721

Affected Products

Activello
Newspaper
The Brilliance