Lucene search

K
wpvulndbPvdlWPVDB-ID:8165A99F-C5AB-43A8-8788-FA9AA22C62AA
HistoryJan 16, 2015 - 12:00 a.m.

CM Download Manager < 2.0.7 - CSRF to Cross-Site Scripting

2015-01-1600:00:00
pvdl
wpscan.com
12

EPSS

0.007

Percentile

80.6%

The lack of CSRF check and sanitisation could allow attackers to perform CSRF attacks against logged in administrators, and set a Cross-Site Scripting payload via addons_title parameter in the CMDM_admin_settings page.

EPSS

0.007

Percentile

80.6%

Related for WPVDB-ID:8165A99F-C5AB-43A8-8788-FA9AA22C62AA