PT-2023-24690 · WordPress · Image Map Pro

CVE-2023-3412

·

Publicado

2023-06-27

·

Atualizado

2025-01-13

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress versions up to, and including, 1.0.0
Description The issue is related to Stored Cross-Site Scripting due to a missing capability check on the ajax store save() function. This allows authenticated attackers with minimal permissions, such as a subscriber, to modify plugin settings and inject malicious web scripts.
Recommendations For versions up to, and including, 1.0.0, consider disabling the ajax store save() function until a patch is available to prevent exploitation. Restrict access to plugin settings to minimize the risk of attackers modifying them and injecting malicious scripts.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3412

Produtos afetados

Image Map Pro