Lucene search

K
cvelistPatchstackCVELIST:CVE-2023-49778
HistoryDec 21, 2023 - 12:37 p.m.

CVE-2023-49778 WordPress Sayfa Sayaç Plugin <= 2.6 is vulnerable to PHP Object Injection

2023-12-2112:37:02
CWE-502
Patchstack
www.cve.org
3
cve-2023-49778
wordpress
php object injection
hakan demiray
sayfa sayac

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.001

Percentile

31.1%

Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "sayfa-sayac",
    "product": "Sayfa Sayac",
    "vendor": "Hakan Demiray",
    "versions": [
      {
        "lessThanOrEqual": "2.6",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.001

Percentile

31.1%

Related for CVELIST:CVE-2023-49778