{"id":3478054,"date":"2013-02-17T13:54:49","date_gmt":"2013-02-17T13:54:49","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/vulnerabilities\/"},"modified":"2016-08-20T21:43:23","modified_gmt":"2016-08-20T21:43:23","slug":"vulnerabilities","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/vulnerabilities\/","title":{"rendered":"Vulnerabilities"},"content":{"rendered":"<p>Hello,<\/p>\n<p>we have used this plugin for some months now. It is doing a good job on our site and is stable.<br \/>\nI stumbled over two problems today:<\/p>\n<ol>\n<li>This plugin is vulnerable to integer injections: It does not check the POST data in AJAX requests. It is possible to inject huge (both positive and negative) ratings through the &#8216;stars&#8217; parameter.<\/li>\n<li>Your PHP code does not check the AJAX source IP. It just tells the browser not to allow rating more often than once. This allows an unlimited number of ratings.<\/li>\n<\/ol>\n<p>Both vulnerabilities allow setting a post&#8217;s rating to any value. Combining them makes it even easier.<\/p>\n<p>Best regards<br \/>\ntniessen<\/p>\n<p>https:\/\/wordpress.org\/extend\/plugins\/kk-star-ratings\/<\/p>\n","protected":false},"template":"","class_list":["post-3478054","topic","type-topic","status-closed","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/3478054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/3478054\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=3478054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}