Lucene search

K
cve[email protected]CVE-2023-5239
HistoryNov 27, 2023 - 5:15 p.m.

CVE-2023-5239

2023-11-2717:15:08
web.nvd.nist.gov
29
security
malware
scan
cleantalk
wordpress
plugin
cve-2023-5239
vulnerability
ip address
header
bypass
brute force
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

17.8%

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

Affected configurations

Vulners
NVD
Node
cleantalksecurity_\&_malware_scanRange<2.121
VendorProductVersionCPE
cleantalksecurity_\&_malware_scan*cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Security & Malware scan by CleanTalk",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "2.121"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

17.8%

Related for CVE-2023-5239