8

CVE-2017-14530

Exploit

Crony Cronjob Manager < 0.4.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting

WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
Mögliche Gegenmaßnahme
Crony Cronjob Manager: Update to version 0.4.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Crony Cronjob Manager ProjectCrony Cronjob Manager SwPlatformwordpress Version <= 0.4.6
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Crony Cronjob Manager
Version [*, 0.4.7)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.469
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8 2.1 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://cybersecurityworks.com/zerodays/cve-2017-14530-crony.html
Third Party Advisory
Exploit
https://github.com/cybersecurityworks/Disclosed/issues/9
Third Party Advisory
Exploit
Technical Description
https://wordpress.org/plugins/crony/#developers
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/b86ff40d-45dd-4cb6-9a4e-16aaf1d35196
Third Party Advisory