OSV 1.4.0 · unreviewed · 修改于 2022-10-26 03:00
发布时间
2022-01-25 08:01
GitHub 审查时间
—
NVD 发布时间
2022-01-24 16:15
源文件
advisories/unreviewed/2022/01/GHSA-chxc-687f-jrfg/GHSA-chxc-687f-jrfg.json
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
该公告没有提供结构化的受影响软件包信息。