6.8

CVE-2013-2706

Stream Video Player <= 1.4.1 - Cross-Site Request Forgery

Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
Mögliche Gegenmaßnahme
Stream Video Player: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rodrigo PoloStream Video Player Version1.4.0
   WordpressWordpress Version-
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Stream Video Player
Version *-1.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.97% 0.573
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

http://osvdb.org/94466
http://secunia.com/advisories/52954
Vendor Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/bae06fa8-546c-4daf-8335-a5e24f6704d4
Third Party Advisory