ZeroHour

CVE-2021-24823

PoC ×2
CVSS 3.1
8.1 high
EPSS
<1%p44
Published
()
Modified
Description

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

Vendors
schiocco
Products
support board
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.