github.com
https://github.com/fireeye/Vulnerability-Disclosures CVE-2021-37598
MEDIUMNuclei
WP Cerber < 8.9.3 - Broken Access Control
Record summary
CVE-2021-37598 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWP Cerber < 8.9.3 - Broken Access ControlCVSS 5.3
WP Cerber < 8.9.3 contains a bypass of /wp-json access control caused by improper handling of trailing '?' character, letting unauthorized users access protected REST API endpoints, exploit requires sending a request with a trailing '?'.
Impact
Unauthorized users can access protected REST API endpoints, potentially leading to information disclosure or further exploitation.
Remediation
Update to version 8.9.3 or later.
WeaknessesCWE-863
Authorstheamanrawat
Template tagscvecve2021wordpresswp-cerberaccess-controlrest-apiexposureauth-bypass
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/FEYE-2021-0024/FEYE-2021-0024.md https://nvd.nist.gov/vuln/detail/CVE-2021-37598
Source: ProjectDiscovery
References
3github.com
https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0024/FEYE-2021-0024.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-37598