漏洞标题
Raptive Ads <= 3.6.3 版本中存在未授权访问并重置数据/设置漏洞
漏洞描述信息
WordPress的Raptive Ads插件在所有版本中,包括3.6.3版本,由于site_ads_files_reset()和cls_file_reset()函数缺少权限验证,存在未授权访问漏洞。这使得未认证的攻击者可以重置广告和cls文件。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
漏洞类别
授权机制缺失
漏洞标题
Raptive Ads <= 3.6.3 - Missing Authorization to Unauthenticated Data/Settings Reset
漏洞描述信息
The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to reset the ad and cls files.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
漏洞类别
授权机制缺失