Headline
CVE-2017-20093: Cross-Site Request Forgery in WordPress Download Manager Plugin
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
Nmap Announce Nmap Dev Full Disclosure Security Lists Internet Issues Open Source Dev
Full Disclosure mailing list archives
From: Summer of Pwnage <lists () securify nl>
Date: Wed, 1 Mar 2017 07:07:14 +0100
------------------------------------------------------------------------ Cross-Site Request Forgery in WordPress Download Manager Plugin
Burak Kelebek, July 2016
Abstract
A Cross-Site Request Forgery vulnerability has been found in the WordPress Download Manager Plugin. By using this vulnerability an attacker can change confidential settings of the plugin.
OVE ID
OVE-20160722-0005
Tested versions
This issue was successfully tested on WordPress Download Manager version 2.8.99.
Fix
There is currently no fix available.
Details
https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_download_manager_plugin.html
Summer of Pwnage (https://sumofpwn.nl) is a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way.
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- Cross-Site Request Forgery in WordPress Download Manager Plugin Summer of Pwnage (Feb 28)