5.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
WordPress Holmes theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Holmes holmes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Holmes: from n/a through <= 1.7.
References
Affected products
- =<<= 1.7
Matching in nixpkgs
pkgs.rubyPackages.charlock_holmes
None
pkgs.rubyPackages_3_1.charlock_holmes
None
pkgs.rubyPackages_3_2.charlock_holmes
None
pkgs.rubyPackages_3_3.charlock_holmes
None
pkgs.rubyPackages_3_4.charlock_holmes
None
pkgs.rubyPackages_3_5.charlock_holmes
None