CVE-2024-6017Cross-Site Request Forgery in Music Request Manager

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 60.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12

Description

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-m2wr-9pq6-49jc: The Music Request Manager WordPress plugin through 12024-09-12
CVEList
Music Request Manager <= 1.3 - Stored XSS via CSRF2024-09-12
CVE-2024-6017 — Cross-Site Request Forgery | cvebase