CVE Feed

    Dashboard / CVE / CVE-2020-8658

    CVE-2020-8658

    The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.

    Published:Feb 6, 2020
    Last Modified:Nov 21, 2024
    EPS:Feb 6, 2020
    EPSS Score:0.01947
    CVSS Score:8.8

    Affected Products

    Vendor
    Bestwebsoft
    Product
    Htaccess

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High