CVE-2024-4750
BuddyBoss Platform < 2.6.0 - Insecure Direct Object Reference on Like Comment
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request
El complemento buddyboss-platform de WordPress anterior a 2.6.0 contiene una vulnerabilidad IDOR que permite a un usuario darle me gusta a una publicación privada manipulando la identificación incluida en la solicitud.
The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the activity_mark_fav AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to like private posts.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-10 CVE Reserved
- 2024-05-14 CVE Published
- 2024-06-04 EPSS Updated
- 2024-08-01 First Exploit
- 2024-08-09 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/ffbe4034-842b-43b0-97d1-208811376dea | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Buddyboss-platform Search vendor "Unknown" for product "Buddyboss-platform" | < 2.6.0 Search vendor "Unknown" for product "Buddyboss-platform" and version " < 2.6.0" | en |
Affected
|