Lucene search

K
wpvulndbWpvulndbWPVDB-ID:29C98F5F-E0BF-479D-B80C-FCF0B2DF2BA8
HistoryJan 04, 2024 - 12:00 a.m.

Crowdsignal Dashboard < 3.1.0 - Rating Update via CSRF

2024-01-0400:00:00
wpscan.com
4
crowdsignal
dashboard
plugin
update_rating
csrf
vulnerability
attackers
admins
logged in users

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Description The plugin does not have CSRF check in its update_rating() function, which could allow attackers to make logged in users admins update ratings via a CSRF attack

CPENameOperatorVersion
eq3.1.0

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for WPVDB-ID:29C98F5F-E0BF-479D-B80C-FCF0B2DF2BA8