CVE-2015-10108

A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to version 0.9.6.1 is able to address this issue. The patch is identified as 2a8057df8ca30adc859cecbe5cad21ac28c5b747. It is recommended to upgrade the affected component. VDB-230234 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inline_google_spreadsheet_viewer_project:inline_google_spreadsheet_viewer:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 02:24

Type Values Removed Values Added
References () https://github.com/wp-plugins/inline-google-spreadsheet-viewer/commit/2a8057df8ca30adc859cecbe5cad21ac28c5b747 - Patch () https://github.com/wp-plugins/inline-google-spreadsheet-viewer/commit/2a8057df8ca30adc859cecbe5cad21ac28c5b747 - Patch
References () https://github.com/wp-plugins/inline-google-spreadsheet-viewer/releases/tag/0.9.6.1 - Release Notes () https://github.com/wp-plugins/inline-google-spreadsheet-viewer/releases/tag/0.9.6.1 - Release Notes
References () https://vuldb.com/?ctiid.230234 - Permissions Required, Third Party Advisory () https://vuldb.com/?ctiid.230234 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.230234 - Permissions Required, Third Party Advisory () https://vuldb.com/?id.230234 - Permissions Required, Third Party Advisory
CVSS v2 : 5.0
v3 : 8.8
v2 : 5.0
v3 : 4.3

07 Nov 2023, 02:23

Type Values Removed Values Added
CWE CWE-352

20 Oct 2023, 10:15

Type Values Removed Values Added
Summary A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to version 0.9.6.1 is able to address this issue. The name of the patch is 2a8057df8ca30adc859cecbe5cad21ac28c5b747. It is recommended to upgrade the affected component. VDB-230234 is the identifier assigned to this vulnerability. A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to version 0.9.6.1 is able to address this issue. The patch is identified as 2a8057df8ca30adc859cecbe5cad21ac28c5b747. It is recommended to upgrade the affected component. VDB-230234 is the identifier assigned to this vulnerability.
CWE CWE-352

06 Jun 2023, 20:08

Type Values Removed Values Added
First Time Inline Google Spreadsheet Viewer Project inline Google Spreadsheet Viewer
Inline Google Spreadsheet Viewer Project
CPE cpe:2.3:a:inline_google_spreadsheet_viewer_project:inline_google_spreadsheet_viewer:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References (MISC) https://github.com/wp-plugins/inline-google-spreadsheet-viewer/commit/2a8057df8ca30adc859cecbe5cad21ac28c5b747 - (MISC) https://github.com/wp-plugins/inline-google-spreadsheet-viewer/commit/2a8057df8ca30adc859cecbe5cad21ac28c5b747 - Patch
References (MISC) https://vuldb.com/?ctiid.230234 - (MISC) https://vuldb.com/?ctiid.230234 - Permissions Required, Third Party Advisory
References (MISC) https://github.com/wp-plugins/inline-google-spreadsheet-viewer/releases/tag/0.9.6.1 - (MISC) https://github.com/wp-plugins/inline-google-spreadsheet-viewer/releases/tag/0.9.6.1 - Release Notes
References (MISC) https://vuldb.com/?id.230234 - (MISC) https://vuldb.com/?id.230234 - Permissions Required, Third Party Advisory

31 May 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-31 19:15

Updated : 2024-11-21 02:24


NVD link : CVE-2015-10108

Mitre link : CVE-2015-10108

CVE.ORG link : CVE-2015-10108


JSON object : View

Products Affected

inline_google_spreadsheet_viewer_project

  • inline_google_spreadsheet_viewer
CWE
CWE-352

Cross-Site Request Forgery (CSRF)