CVE-2024-29009

Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to perform unintended operations if the administrator views a malicious page while logged in.
Configurations

No configuration.

History

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN86206017/ - () https://jvn.jp/en/jp/JVN86206017/ -
References () https://wordpress.org/plugins/easy-popup-show/ - () https://wordpress.org/plugins/easy-popup-show/ -

27 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-352

25 Mar 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de Cross-Site Request Forgery (CSRF) en easy-popup-show todas las versiones permite a un atacante remoto no autenticado secuestrar la autenticación del administrador y realizar operaciones no deseadas si el administrador ve una página maliciosa mientras está conectado.

25 Mar 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-25 05:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-29009

Mitre link : CVE-2024-29009

CVE.ORG link : CVE-2024-29009


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)