CVE-2024-11638
CVE-2024-11638
Título es
CVE-2024-11638
Lun, 10/03/2025 – 06:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-11638
Descripción en
The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.
10/03/2025
10/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://wpscan.com/vulnerability/2f20336f-e12e-4b09-bcaf-45f7249f6495/
Enviar en el boletín
Off
