PT-2023-17044 · WordPress · Gmace

·

CVE-2023-1509

·

Publicado

2023-03-29

·

Atualizado

2023-04-05

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GMAce plugin for WordPress versions up to, and including, 1.5.2
Description The issue is due to missing nonce validation on the gmace manager server function called via the wp ajax gmace manager AJAX action. This allows unauthenticated attackers to modify arbitrary files and achieve remote code execution via a forged request, provided they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For GMAce plugin for WordPress versions up to, and including, 1.5.2, consider disabling the gmace manager server function until a patch is available to prevent exploitation via the wp ajax gmace manager AJAX action. Restrict access to the wp ajax gmace manager AJAX action to minimize the risk of exploitation.

Correção

RCE

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1509

Produtos afetados

Gmace