OSV 1.4.0 · unreviewed · 修改于 2022-02-20 08:00
发布时间
2022-02-15 08:02
GitHub 审查时间
—
NVD 发布时间
2022-02-14 20:15
源文件
advisories/unreviewed/2022/02/GHSA-gvfj-h2wq-cw77/GHSA-gvfj-h2wq-cw77.json
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored XSS issues
该公告没有提供结构化的受影响软件包信息。