PT-2026-93763 · Adenion · Blog2Social
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s calendar move post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s posts table using only the attacker-supplied b2s id primary key with no blog user id ownership constraint, allowing any user with the edit posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blog2Social