Realteo < 1.2.4 - Missing Authorization

2021-03-20 00:00
R3N0

Strategic Overview

Status
Patched in 1.2.4
Affected PluginRealteo
Affected Version< 1.2.4
CVSS6.5Medium
CVECVE-2021-24238
View all Realteo vulnerabilities

Vulnerability Overview

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter.

Technical Analysis

REMEDIATION: Update to version 1.2.4, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C