vendor:
ALO EasyMail Newsletter
by:
Securify
7,5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: ALO EasyMail Newsletter
Affected Version From: 2.9.2
Affected Version To: 2.9.2
Patch Exists: YES
Related CWE: N/A
CPE: a:alo-group:alo-easymail-newsletter
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2016
Cross-Site Request Forgery in ALO EasyMail Newsletter WordPress Plugin
It was discovered that the ALO EasyMail Newsletter WordPress Plugin is vulnerable to Cross-Site Request Forgery. Amongst others, this issue can be used to add/import arbitrary subscribers. In order to exploit this issue, the attacker has to lure/force a victim into opening a malicious website/link.
Mitigation:
This issue is resolved in ALO EasyMail Newsletter version 2.9.3.