CVE-2017-6955

An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:teleogistic:invite_anyone:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 03:30

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/96965 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/96965 - Third Party Advisory, VDB Entry
References () https://github.com/boonebgorges/invite-anyone/compare/2ed5266ad3ae40f8db39adf06f450bbad56e2eac...boonebgorges:6121de08df86c5005b657dd67e48aa02c7982855 - Third Party Advisory () https://github.com/boonebgorges/invite-anyone/compare/2ed5266ad3ae40f8db39adf06f450bbad56e2eac...boonebgorges:6121de08df86c5005b657dd67e48aa02c7982855 - Third Party Advisory
References () https://wordpress.org/plugins/invite-anyone/changelog/ - Release Notes, Third Party Advisory () https://wordpress.org/plugins/invite-anyone/changelog/ - Release Notes, Third Party Advisory

Information

Published : 2017-03-17 09:59

Updated : 2024-11-21 03:30


NVD link : CVE-2017-6955

Mitre link : CVE-2017-6955

CVE.ORG link : CVE-2017-6955


JSON object : View

Products Affected

teleogistic

  • invite_anyone
CWE
CWE-20

Improper Input Validation