vendor:
Simple Share Buttons Adder
by:
dxw
5,8
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS)
352, 79
CWE
Product Name: Simple Share Buttons Adder
Affected Version From: 4.4
Affected Version To: 4.4
Patch Exists: YES
Related CWE: Awaiting assignment
CPE: a:dxw:simple_share_buttons_adder
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
CSRF and stored XSS in Simple Share Buttons Adder 4.4
An attacker able to convince an admin to visit a link of their choosing is able to execute arbitrary javascript in the context of the Homepage, Pages, Posts, Category/Archive pages and post Excerpts.
Mitigation:
Immediately upgrade to version 4.5 or greater.