WordPress Plugin Vulnerabilities

CM Download Manager < 2.0.7 - CSRF to Cross-Site Scripting

Description

The lack of CSRF check and sanitisation could allow attackers to perform CSRF attacks against logged in administrators, and set a Cross-Site Scripting payload via addons_title parameter in the CMDM_admin_settings page.

Affects Plugins

Fixed in 2.0.7

References

Miscellaneous

Submitter
pvdl
Verified
No

Timeline

Publicly Published
2015-01-16 (about 11 years ago)
Added
2015-01-16 (about 11 years ago)
Last Updated
2020-10-22 (about 5 years ago)

Other