6
CVE-2021-24446
- EPSS 0.08%
- Veröffentlicht 14.02.2022 12:15:14
- Zuletzt bearbeitet 21.11.2024 05:53:05
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Remove Footer Credit <= 1.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation
Mögliche Gegenmaßnahme
Remove Footer Credit: Update to version 1.0.6, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Remove Footer Credit
Version
* - 1.0.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpchill ≫ Remove Footer Credit SwPlatformwordpress Version < 1.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.252 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.