Description
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.
Remediation
References
Related Vulnerabilities
WordPress Plugin All Video Gallery 'vid' Parameter Multiple SQL Injection Vulnerabilities (1.1)
Jenkins Incorrect Authorization Vulnerability (CVE-2021-21692 )
WordPress Plugin YITH PayPal Express Checkout for WooCommerce Security Bypass (1.2.5)
WordPress Plugin ChimpMate-WordPress MailChimp Assistant Local File Inclusion (1.3.2)
WordPress Plugin Analytics Stats Counter Statistics PHP Object Injection (1.2.2.5)