Podatność CVE-2022-1579


Publikacja: 2022-11-21

Opis:
The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

Typ:

CWE-639

(Authorization Bypass Through User-Controlled Key)

 Referencje:
https://wpscan.com/vulnerability/6f3d40fa-458b-44f0-9407-763e80b29668

Copyright 2024, cxsecurity.com

 

Back to Top