Lucene search

K
nvd[email protected]NVD:CVE-2023-5340
HistoryNov 20, 2023 - 7:15 p.m.

CVE-2023-5340

2023-11-2019:15:09
CWE-74
web.nvd.nist.gov
1
cve-2023-5340
five star restaurant menu
food ordering
wordpress plugin
ajax action
unauthenticated users
php object injection
gadget

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.7%

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

Affected configurations

NVD
Node
fivestarpluginsfive_star_restaurant_menuRange<2.4.11wordpress

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.7%

Related for NVD:CVE-2023-5340