CVE-2021-24767
Redirect 404 Error Page to Homepage or Custom Page with Logs < 1.7.9 - Log Deletion via CSRF
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
08 nov 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack
Productos afectados
Unknown · Redirect 404 Error Page to Homepage or Custom Page with Logs¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →