Lucene search

K
nvd[email protected]NVD:CVE-2023-5239
HistoryNov 27, 2023 - 5:15 p.m.

CVE-2023-5239

2023-11-2717:15:08
web.nvd.nist.gov
3
cleantalk plugin
ip address retrieval
untrusted headers
bruteforce protection
cve-2023-5239

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

17.8%

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

Affected configurations

NVD
Node
cleantalksecurity_\&_malware_scanRange2.121wordpress

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

17.8%

Related for NVD:CVE-2023-5239