The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11735 | The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:42:17.351Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-24823
No data.
Status : Modified
Published: 2022-02-28T09:15:07.737
Modified: 2024-11-21T05:53:49.970
Link: CVE-2021-24823
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD