CVE-2022-1577
Database Backup for WordPress < 2.5.2 - Arbitrary Schedule Settings Update via CSRF
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup schedule
El plugin Database Backup para WordPress versiones anteriores a 2.5.2, no presenta una comprobación de tipo CSRF cuando es actualizada la configuración de las copias de seguridad programadas, lo que podría permitir a un atacante hacer que un administrador conectado las cambie por medio de un ataque de tipo CSRF. Esto podría conllevar casos en los que los atacantes puedan enviarse a sí mismos correos electrónicos de notificación de copias de seguridad, que contienen más detalles. O deshabilitar la programación de copias de seguridad automáticas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-04 CVE Reserved
- 2022-05-11 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/39388900-266d-4308-88e7-d40ca6bbe346 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Deliciousbrains Search vendor "Deliciousbrains" | Database Backup Search vendor "Deliciousbrains" for product "Database Backup" | < 2.5.2 Search vendor "Deliciousbrains" for product "Database Backup" and version " < 2.5.2" | wordpress |
Affected
|