No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51547 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22506 Reason: This candidate is a reservation duplicate of CVE-2025-22506. Notes: All CVE users should reference CVE-2025-22506 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |
No reference.
Thu, 30 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Smart Agenda – Prise de rendez-vous en ligne <= 4.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting | |
| Metrics |
ssvc
|
Thu, 30 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Thu, 30 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the smartagenda_options_page_html() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22506 Reason: This candidate is a reservation duplicate of CVE-2025-22506. Notes: All CVE users should reference CVE-2025-22506 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |
Tue, 14 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the smartagenda_options_page_html() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Smart Agenda – Prise de rendez-vous en ligne <= 4.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: REJECTED
Assigner: Wordfence
Published:
Updated: 2025-01-30T15:05:18.960Z
Reserved: 2025-01-13T15:03:39.599Z
Link: CVE-2024-13348
Updated:
Status : Rejected
Published: 2025-01-14T04:15:09.200
Modified: 2025-01-30T15:15:16.223
Link: CVE-2024-13348
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD