漏洞标题
I Am Gloria <= 1.1.4跨站请求伪造漏洞
漏洞描述信息
WordPress使用的I Am Gloria插件在所有版本(包括1.1.4版本)中存在跨站请求伪造漏洞。该漏洞是由于iamgloria23_gloria_settings_page函数中缺少或验证不正确的随机数(nonce)引起的。这使得未认证的攻击者可以通过伪造请求重置租户ID,前提是攻击者能够诱使网站管理员执行某些操作,如点击链接。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
漏洞类别
跨站请求伪造(CSRF)
漏洞标题
I Am Gloria <= 1.1.4 - Cross-Site Request Forgery
漏洞描述信息
The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the iamgloria23_gloria_settings_page function. This makes it possible for unauthenticated attackers to reset the tenant ID via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
漏洞类别
跨站请求伪造(CSRF)