Description
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23829 | The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog. |
References
History
Fri, 08 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-08T18:23:26.292Z
Reserved: 2023-03-23T09:59:01.878Z
Link: CVE-2023-1597
Updated: 2024-08-02T05:57:24.078Z
Status : Modified
Published: 2023-07-10T16:15:48.890
Modified: 2024-11-21T07:39:30.943
Link: CVE-2023-1597
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD