Lucene search

K
wpvulndbWpvulndbWPVDB-ID:0B34445A-D91D-47C0-8301-13D442FE58CB
HistorySep 21, 2022 - 12:00 a.m.

Demon Image Annotation < 4.8 - Arbitrary Settings Update to Stored XSS via CSRF

2022-09-2100:00:00
wpscan.com
4
demon image annotation
csrf protection
settings update
stored xss
software

0.002 Low

EPSS

Percentile

60.8%

The plugin does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping in some of them, it could also lead to Stored Cross-Site Scripting

CPENameOperatorVersion
demon-image-annotationlt4.8

0.002 Low

EPSS

Percentile

60.8%

Related for WPVDB-ID:0B34445A-D91D-47C0-8301-13D442FE58CB