Cross Site Request Forgery (CSRF) nel plugin a due fattori-autenticazione prima 1.3.13 per WordPress consente agli aggressori remoti per disabilitare 2FA tramite il parametro tfa_enable_tfa a causa di convalida nonce mancante. |
https://wordpress.org/plugins/two-factor-authentication/#developers https://wpvulndb.com/vulnerabilities/9187 https://www.privacy-wise.com/two-factor-authentication-cross-site-request-forgery-csrf-vulnerability-cve-2018-20231/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20231 |
Vulnerabilità: CVE-2018-20231
