The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cminds
Cminds cm Table Of Contents |
|
CPEs | cpe:2.3:a:cminds:cm_table_of_contents:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cminds
Cminds cm Table Of Contents |
|
Metrics |
cvssV3_1
|
Thu, 21 Nov 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
Title | CM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-21T21:48:56.832Z
Reserved: 2024-05-16T19:31:13.629Z
Link: CVE-2024-5029

Updated: 2024-11-21T21:48:49.074Z

Status : Awaiting Analysis
Published: 2024-11-21T11:15:35.790
Modified: 2024-11-21T22:15:09.660
Link: CVE-2024-5029

No data.