Beveiligingsadvies

CVE-2022-0229

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-03-21 18:55:42
Laatst bijgewerkt 2024-08-02 23:18:42
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.