CVE-2015-20105

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
References
Link Resource
https://packetstormsecurity.com/files/131814/ Exploit Third Party Advisory VDB Entry
https://seclists.org/bugtraq/2015/May/45 Exploit Mailing List Third Party Advisory
https://wpscan.com/vulnerability/2bc3af7e-5542-40c4-8141-7c49e8df68f0 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cbads:clickbank_affiliate_ads:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-12-02 18:15

Updated : 2024-02-28 18:48


NVD link : CVE-2015-20105

Mitre link : CVE-2015-20105

CVE.ORG link : CVE-2015-20105


JSON object : View

Products Affected

cbads

  • clickbank_affiliate_ads
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')