ZeroHour

CVE-2020-14205

PoC
CVSS 3.1
5.3 medium
EPSS
1%p65
Published
()
Modified
Description

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

Vendors
divebook project
Products
divebook
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.