WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
BID:71418
Info
WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 71418 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9129 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2014 12:00AM |
| Updated: | Dec 02 2014 12:00AM |
| Credit: | Henri Salo |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
CM Download Manager plugin for WordPress is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
CM Download Manager 2.0.6 and prior versions are vulnerable.
CM Download Manager plugin for WordPress is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
CM Download Manager 2.0.6 and prior versions are vulnerable.
Exploit / POC
WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
To exploit this issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
To exploit this issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
Solution / Fix
WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
References:
References: