CVE-2014-5347
Published Aug 19, 2014
Last updated 7 years ago
Overview
- Description
- Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3) disqus_secret_key parameter to wp-admin/edit-comments.php in manage.php or that (4) reset or (5) delete plugin options via the reset parameter to wp-admin/edit-comments.php.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:*:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "E9F43198-0635-468C-966A-09FA8D56B156", "versionEndIncluding": "2.75" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.40:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "4D133D9B-D85E-4DAE-9FB8-06901A1D9C9B" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.41:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "3F110C72-E5A2-4E35-A7F7-82F5D4F94252" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.42:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "A1975849-A2BE-437F-B9C9-658E7A863301" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.43:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "A6D0D687-432A-4D6C-B538-B4CFDCF49924" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.44:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "60832509-508D-49A7-9B0C-8005CE0B68A5" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.45:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "E4A116A3-7238-4C61-BC05-16FA0ABDC5F3" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.46:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "98F3F106-02F6-4E3A-94F3-3C85D288398F" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.47:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "52BA133C-A454-4CC1-A689-AB96ED43B911" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.48:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "DF96D06B-4CE6-4E7C-8F2E-89BED63CB8BF" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.49:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "87230BBD-FB7F-475B-9829-29C9A26C732B" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.50:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "253BAFE4-F0DB-4B62-8E96-8815B0DE4A3E" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.51:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "D6CCB19B-886B-4DD0-877C-67C480CF3C84" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.52:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "71109895-84FA-43B6-BC07-5715B4E322B0" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.53:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "A2F94F08-39F3-4588-8D2C-547CC224E088" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.54:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "D260F61A-DE2C-4683-8E04-43EA0F1902FB" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.55:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "C50AF188-A524-481B-96EF-636FB749645F" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.60:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "54C18DDB-3E72-4B23-BA48-BE0B02C5CA9F" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.61:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "C58C4A85-DC85-4512-B614-67C518135060" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.62:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "58FADDF1-D4C9-4165-9239-6148FFC08599" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.63:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "EA46A51C-8F26-4EB5-866D-4C9067EFAB47" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.64:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "EAAA1734-E127-4198-A39E-AF96F9DE7679" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.65:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "324AD796-9EB9-440E-94A6-67423EB94ABF" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.66:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "FAF97FAB-FC98-4741-9956-3427B2A83104" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.67:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "69083A3A-BD8D-47F0-96E6-322BE46DA05C" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.68:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "745EB413-FD96-4192-8C06-CAE5941B8CD3" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.69:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "21DB96C1-679E-4492-BD8A-D798A6F56926" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.70:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "792610E2-85D7-41F0-B8F6-280785496A39" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.71:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "D00EDD63-18EC-43EE-A501-09C0F429EFA8" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.72:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "EA1FB9C2-5DBD-4941-B777-0B1B4CFED16C" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.73:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "156A1D4F-6AC3-47A4-B7D7-48EDEF6401E7" }, { "criteria": "cpe:2.3:a:disqus:disqus_comment_system:2.74:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "BB069EA4-2BED-47B8-A715-D14207C24569" } ], "operator": "OR" } ] } ]