ZeroHour

CVE-2022-3024

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p17
Published
()
Modified
Description

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

Vendors
simple bitcoin faucets project
Products
simple bitcoin faucets
Ecosystems
WordPress
Weakness
CWE-352, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.