Quantcast
Channel: Security Bulletins
Viewing all articles
Browse latest Browse all 25

Spiceworks Website WordPress Publisher Vulnerability

$
0
0

Publish Date: July 12, 2019

Summary

We've identified a vulnerability in the Spiceworks WWW site that would allow an attacker to view the names of people who have published articles through WordPress on the Spiceworks site.

Who’s Affected?

At this time, we do not believe anyone was affected by this vulnerability.

Details

An attacker could utilize a vulnerable WordPress API that was left publicly accessible on the Spiceworks WWW site to gain the username, first name, and last name of people who have published through WordPress on the site. The attacker could use this information to make compromising the site easier.

Mitigating Factors

In order to exploit this vulnerability, the attacker would have to purposefully enter the URL of the susceptible API.

Security Update Information

Due to the coordinated disclosure of this vulnerability,...


Viewing all articles
Browse latest Browse all 25

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>