6.5
CVE-2024-6490
- EPSS 0.22%
- Veröffentlicht 26.07.2024 06:15:02
- Zuletzt bearbeitet 27.05.2025 16:32:41
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Master Slider – Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion
During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Averta ≫ Master Slider SwPlatformwordpress Version < 3.10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.117 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
https://wpscan.com/vulnerability/5a56e5aa-841d-4be5-84da-4c3b7602f053/