Aller au contenu

Fiche vulnérabilité

CVE-2022-3911 : faille élevée iubenda iubenda-cookie-law-solution (CVSS 8.8)

Description

The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etc

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
2 janv. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • iubenda iubenda-cookie-law-solution

Références

Rechercher une autre vulnérabilité dans la base CVE