Ver todas as ameaças

CVE-2020-35947

Alvo: Não informado

Descrição

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2020-35947
Tags
Nâo informado
Data de publicação
01/01/2021
Última atualização
08/12/2024
Pontuação em CVSS 3.0
7.4
Alto
Rolar para cima