The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files
Advisories
Source ID Title
EUVD EUVD EUVD-2021-11735 The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:42:17.351Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24823

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-28T09:15:07.737

Modified: 2024-11-21T05:53:49.970

Link: CVE-2021-24823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.