The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
History

Fri, 27 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:*

Fri, 13 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Pixeljar
Pixeljar favicon Generator
CPEs cpe:2.3:a:favicon_generator_wordpress_plugin:favicon_generator_wordpress_plugin:*:*:*:*:*:*:*:* cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:*:*:*
Vendors & Products Favicon Generator Wordpress Plugin
Favicon Generator Wordpress Plugin favicon Generator Wordpress Plugin
Pixeljar
Pixeljar favicon Generator

Fri, 13 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Favicon Generator Wordpress Plugin
Favicon Generator Wordpress Plugin favicon Generator Wordpress Plugin
Weaknesses CWE-352
CPEs cpe:2.3:a:favicon_generator_wordpress_plugin:favicon_generator_wordpress_plugin:*:*:*:*:*:*:*:*
Vendors & Products Favicon Generator Wordpress Plugin
Favicon Generator Wordpress Plugin favicon Generator Wordpress Plugin
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
Title Favicon Generator < 2.1 - Arbitrary File Deletion via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-13T06:00:04.341Z

Updated: 2024-09-13T15:41:24.874Z

Reserved: 2024-08-15T18:47:41.627Z

Link: CVE-2024-7864

cve-icon Vulnrichment

Updated: 2024-09-13T14:12:51.336Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T06:15:15.720

Modified: 2024-09-27T21:26:50.067

Link: CVE-2024-7864

cve-icon Redhat

No data.