minor update

patch-4
Dhiyaneshwaran 2024-06-11 21:32:39 +05:30 committed by GitHub
parent 7f6a1ace74
commit 0a69f50acb
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 1 additions and 2 deletions

View File

@ -2,7 +2,7 @@ id: CVE-2023-6505
info: info:
name: Prime Mover < 1.9.3 - Sensitive Data Exposure name: Prime Mover < 1.9.3 - Sensitive Data Exposure
author: securityforeveryone.com author: securityforeveryone
severity: high severity: high
description: | description: |
Prime Mover plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.2 via directory listing in the 'prime-mover-export-files/1/' folder. This makes it possible for unauthenticated attackers to extract sensitive data including site and configuration information, directories, files, and password hashes. Prime Mover plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.2 via directory listing in the 'prime-mover-export-files/1/' folder. This makes it possible for unauthenticated attackers to extract sensitive data including site and configuration information, directories, files, and password hashes.
@ -11,7 +11,6 @@ info:
reference: reference:
- https://wpscan.com/vulnerability/eca6f099-6af0-4f42-aade-ab61dd792629 - https://wpscan.com/vulnerability/eca6f099-6af0-4f42-aade-ab61dd792629
- https://research.cleantalk.org/cve-2023-6505-prime-mover-poc-exploit/ - https://research.cleantalk.org/cve-2023-6505-prime-mover-poc-exploit/
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://nvd.nist.gov/vuln/detail/CVE-2023-6505 - https://nvd.nist.gov/vuln/detail/CVE-2023-6505
classification: classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N