The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-12-08T19:46:28
Updated: 2024-08-04T12:39:36.203Z
Reserved: 2020-06-16T00:00:00
Link: CVE-2020-14205
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-08T20:15:15.167
Modified: 2024-11-21T05:02:51.940
Link: CVE-2020-14205
Redhat
No data.