CVE-2015-9455 - CERT CVE
ID CVE-2015-9455
Sažetak The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
Reference
CVSS
Base: 7.8
Impact: 7.8
Exploitability:8.6
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL COMPLETE
CVSS vektor AV:N/AC:M/Au:N/C:N/I:P/A:C
Zadnje važnije ažuriranje 10-10-2019 - 20:38
Objavljeno 07-10-2019 - 15:15