vendor:
Custom JS Plugin
by:
Abhishek Joshi
N/A
CVSS
N/A
Cross-Site Request Forgery (CSRF)
CWE
Product Name: Custom JS Plugin
Affected Version From: 0.1
Affected Version To: 0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro + XAMPP + PHP Version 7.4.10
2021
GetSimple CMS Custom JS Plugin 0.1 – ‘customhs_js_content’ Cross-Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in Custom JS v0.1 plugin for GetSimple CMS allows remote attackers to inject arbitrary client-side script code into every webpage hosted on the CMS (Persistent Cross-Site Scripting), when an authenticated admin visiting a third-party site.