OSV 1.4.0 · unreviewed · 修改于 2021-12-05 08:00
发布时间
2021-12-03 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-03 02:15
源文件
advisories/unreviewed/2021/12/GHSA-mxrp-jrwv-r3r4/GHSA-mxrp-jrwv-r3r4.json
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
该公告没有提供结构化的受影响软件包信息。