CN
CyberNewsUz
Threat Intelligence Portal
LOADING0%
CyberNewsUz
Threat Intelligence Portal
CyberNewsUz
Threat Intelligence Portal
Uchrashuvlarni bron qilish taqvimi β WordPress uchun Simply Schedule Uchrashuvlarni bron qilish plagini 1.6.9.29 gacha bo'lgan barcha versiyalarda Insecure Direct Object Referencega zaif. Buning sababi, `get_item_permissions_check` usuli so'ralgan uchrashuvga xodimlarning egalik huquqini tasdiqlamasdan `ssa_manage_appointments` imkoniyatiga ega foydalanuvchilarga kirish huquqini beradi. Bu maxsus darajadagi kirish va undan yuqori darajadagi autentifikatsiyalangan hujumchilar uchun imkon beradi (foydalanuvchilarga ssa_m berilgan).
Vendor
β
Product
β
CVSS Score
4.3
Nashr sanasi
13-mar, 2026
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N