← volver
CVE-2024-11638

Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeover

CVSS 8.8 HIGHEPSS 0.5%
The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
Unknown · Gtbabel

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →