CVE-2024-7864

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:*

History

27 Sep 2024, 21:26

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/6ce62e78-04a4-46b2-b97f-c4ef8f3258c3/ - () https://wpscan.com/vulnerability/6ce62e78-04a4-46b2-b97f-c4ef8f3258c3/ - Exploit, Third Party Advisory
First Time Pixeljar favicon Generator
Pixeljar
CPE cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:*

13 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Sep 2024, 14:06

Type Values Removed Values Added
Summary
  • (es) El complemento Favicon Generator (CLOSED) de WordPress anterior a la versión 2.1 no tiene CSRF ni validación de ruta en la función output_sub_admin_page_0(), lo que permite a los atacantes hacer que los administradores que hayan iniciado sesión eliminen archivos arbitrarios en el servidor.

13 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-13 06:15

Updated : 2024-09-27 21:26


NVD link : CVE-2024-7864

Mitre link : CVE-2024-7864

CVE.ORG link : CVE-2024-7864


JSON object : View

Products Affected

pixeljar

  • favicon_generator
CWE
CWE-352

Cross-Site Request Forgery (CSRF)