Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24197
HistoryApr 12, 2021 - 1:58 p.m.

CVE-2021-24197 wpDataTables < 3.4.2 - Improper Access Control leading to Table Permission Takeover

2021-04-1213:58:04
CWE-284
WPScan
www.cve.org
3
wpdatatables
wordpress
access control
table permission takeover
security vulnerability

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

44.0%

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

CNA Affected

[
  {
    "product": "wpDataTables – Tables & Table Charts",
    "vendor": "wpDataTables",
    "versions": [
      {
        "lessThan": "3.4.2",
        "status": "affected",
        "version": "3.4.2",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

44.0%

Related for CVELIST:CVE-2021-24197