CVE-2015-20105

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
References
Link Resource
https://packetstormsecurity.com/files/131814/ Exploit Third Party Advisory VDB Entry
https://seclists.org/bugtraq/2015/May/45 Exploit Mailing List Third Party Advisory
https://wpscan.com/vulnerability/2bc3af7e-5542-40c4-8141-7c49e8df68f0 Exploit Third Party Advisory
https://packetstormsecurity.com/files/131814/ Exploit Third Party Advisory VDB Entry
https://seclists.org/bugtraq/2015/May/45 Exploit Mailing List Third Party Advisory
https://wpscan.com/vulnerability/2bc3af7e-5542-40c4-8141-7c49e8df68f0 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cbads:clickbank_affiliate_ads:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:26

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/131814/ - Exploit, Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/131814/ - Exploit, Third Party Advisory, VDB Entry
References () https://seclists.org/bugtraq/2015/May/45 - Exploit, Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2015/May/45 - Exploit, Mailing List, Third Party Advisory
References () https://wpscan.com/vulnerability/2bc3af7e-5542-40c4-8141-7c49e8df68f0 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/2bc3af7e-5542-40c4-8141-7c49e8df68f0 - Exploit, Third Party Advisory

Information

Published : 2021-12-02 18:15

Updated : 2024-11-21 02:26


NVD link : CVE-2015-20105

Mitre link : CVE-2015-20105

CVE.ORG link : CVE-2015-20105


JSON object : View

Products Affected

cbads

  • clickbank_affiliate_ads
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-352

Cross-Site Request Forgery (CSRF)