Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2017-20093: Cross-Site Request Forgery in WordPress Download Manager Plugin

A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.

CVE
#vulnerability#web#wordpress

Nmap Announce Nmap Dev Full Disclosure Security Lists Internet Issues Open Source Dev

Full Disclosure mailing list archives

From: Summer of Pwnage <lists () securify nl>
Date: Wed, 1 Mar 2017 07:07:14 +0100

------------------------------------------------------------------------ Cross-Site Request Forgery in WordPress Download Manager Plugin


Burak Kelebek, July 2016


Abstract

A Cross-Site Request Forgery vulnerability has been found in the WordPress Download Manager Plugin. By using this vulnerability an attacker can change confidential settings of the plugin.


OVE ID

OVE-20160722-0005


Tested versions

This issue was successfully tested on WordPress Download Manager version 2.8.99.


Fix

There is currently no fix available.


Details

https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_download_manager_plugin.html


Summer of Pwnage (https://sumofpwn.nl) is a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way.

_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

Current thread:

  • Cross-Site Request Forgery in WordPress Download Manager Plugin Summer of Pwnage (Feb 28)

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda