A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
References
Link | Resource |
---|---|
http://get-simple.info/extend/plugin/my-smtp-contact/1221/ | Exploit Third Party Advisory |
http://get-simple.info/extend/plugin/my-smtp-contact/1221/ | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 06:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://get-simple.info/extend/plugin/my-smtp-contact/1221/ - Exploit, Third Party Advisory |
Information
Published : 2021-08-10 23:15
Updated : 2024-11-21 06:01
NVD link : CVE-2021-29400
Mitre link : CVE-2021-29400
CVE.ORG link : CVE-2021-29400
JSON object : View
Products Affected
netexplorer
- my_smtp_contact
CWE
CWE-352
Cross-Site Request Forgery (CSRF)