vendor:
FAQs Manager
by:
m3tamantra
N/A
CVSS
N/A
CSRF, XSS
CWE
Product Name: FAQs Manager
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Apache/2.2.16 (Debian) PHP 5.3.3-7+squeeze14 with Suhosin-Patch (cli)
2013
WordPress IndiaNIC FAQ 1.0 Plugin CSRF + XSS
IndiaNIC FAQ Settings Page is vulnerable for CSRF. The Ask Question area (front-end) is vulnerable for XSS. It is possible to insert <script>alert(1)</script> in question parameter. The Captcha value can be read from captcha parameter (hidden field).