CVE-2021-24328
Summary
| CVE | CVE-2021-24328 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-01 14:15:00 UTC |
| Updated | 2023-11-07 03:31:00 UTC |
| Description | The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well |
Risk And Classification
Problem Types: CWE-352 | CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Clogica | Wp Login Security And History | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| m0ze@blackcore:~# WP Login Security and History v1.0 CSRF PoC | MISC | m0ze.ru | |
| Attention Required! | Cloudflare | CONFIRM | wpscan.com | |
| m0ze.ru/vulnerability/%5B2021-03-29%5D-%5BWordPress%5D-%5BCWE-79%5D-W... | MISC | m0ze.ru | |
| m0ze.ru/vulnerability/[2021-03-29]-[WordPress]-[CWE-352]-WP-Login-Sec... | MISC | m0ze.ru | Broken Link |
| Страница 404 | m0ze.ru | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: m0ze
There are currently no legacy QID mappings associated with this CVE.