The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.
History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-18T19:05:49.195Z

Updated: 2024-08-02T15:24:33.234Z

Reserved: 2024-01-24T11:59:39.530Z

Link: CVE-2024-0858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-18T19:15:06.530

Modified: 2024-11-21T08:47:31.207

Link: CVE-2024-0858

cve-icon Redhat

No data.