PT-2023-11867 · Unknown · Ti Woocommerce Wishlist

·

CVE-2020-36725

·

Publicado

2023-06-07

·

Atualizado

2023-06-16

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TI WooCommerce Wishlist versions up to 1.21.11 TI WooCommerce Wishlist Pro versions up to 1.21.4
Description The issue allows authenticated attackers to gain restricted access to the vulnerable blog and update any settings due to an Options Change vulnerability. This is possible via the 'ti-woocommerce-wishlist/includes/export.class.php' file.
Recommendations For TI WooCommerce Wishlist versions up to 1.21.11, update to a version later than 1.21.11 to resolve the issue. For TI WooCommerce Wishlist Pro versions up to 1.21.4, update to a version later than 1.21.4 to resolve the issue. As a temporary workaround, consider restricting access to the export.class.php file until a patch is available.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-36725

Produtos afetados

Ti Woocommerce Wishlist