ZeroHour

CVE-2021-29400

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p45
Published
()
Modified
Description

A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.

Vendors
netexplorer
Products
my smtp contact
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.