6.5
CVSSv3

CVE-2022-2555

Published: 22/08/2022 Updated: 23/08/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Yotpo Reviews for WooCommerce WordPress plugin up to and including 2.0.4 lacks nonce check when updating its settings, which could allow malicious user to make a logged in admin change them via a CSRF attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yotpo reviews for woocommerce project yotpo reviews for woocommerce

Github Repositories

针对部署在Weblogic上的Shiro

VRV Shiro_Weblogic_Tool 针对部署在Weblogic上的shiro漏洞 简介 日常项目中,可能会碰见部署在weblogic上的shiro,所以先写了这个生成攻击payload的小Demo,方便后面使用。 免责声明 本工具仅能在取得足够合法授权的企业安全建设中使用,在使用本工具过程中,您应确保自己所有行为符合当地的法律