漏洞标题
WordPress Push Notification for Post and BuddyPress插件 <= 2.11版本设置修改漏洞
漏洞描述信息
Murali Push Notification for Post 和 BuddyPress 中存在授权缺失漏洞,允许利用配置不当的访问控制安全级别进行攻击。此问题影响 Push Notification for Post 和 BuddyPress 版本从 n/a 到 2.11。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
漏洞类别
授权机制缺失
漏洞标题
WordPress Push Notification for Post and BuddyPress plugin <= 2.11 - Settings Change vulnerability
漏洞描述信息
Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Push Notification for Post and BuddyPress: from n/a through 2.11.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
漏洞类别
授权机制缺失