The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cminds
Cminds cm Table Of Contents |
|
CPEs | cpe:2.3:a:cminds:cm_table_of_contents:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cminds
Cminds cm Table Of Contents |
|
Metrics |
cvssV3_1
|
Thu, 21 Nov 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
Title | CM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-11-21T06:00:07.135Z
Updated: 2024-11-21T21:48:56.832Z
Reserved: 2024-05-16T19:31:13.629Z
Link: CVE-2024-5029
Vulnrichment
Updated: 2024-11-21T21:48:49.074Z
NVD
Status : Awaiting Analysis
Published: 2024-11-21T11:15:35.790
Modified: 2024-11-21T22:15:09.660
Link: CVE-2024-5029
Redhat
No data.