vendor:
Contact Form Manager
by:
Securify
8,8
CVSS
HIGH
Cross-Site Request Forgery and Cross-Site Scripting
352, 79
CWE
Product Name: Contact Form Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Cross-Site Request Forgery and Cross-Site Scripting in Contact Form Manager WordPress Plugin
It was discovered that Contact Form Manager does not protect against Cross-Site Request Forgery. This allows an attacker to change arbitrary Contact Form Manager settings. In addtion, the plugin also fails to apply proper output encoding, rendering it vulnerable to stored Cross-Site Scripting. The username input field on the XYZ Contact > SMTP Settings is vulnerabile to stored Cross-Site Scripting.
Mitigation:
There is currently no fix available.