vendor:
Mathjax Latex
by:
Junaid Hussain
7,5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Mathjax Latex
Affected Version From: 1.1
Affected Version To: 1.2.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOs 5 - Wordpress Version 3.5
2013
WordPress Mathjax Latex 1.1 Cross-Site Request Forgery Vulnerability
There is no CSRF protection on the mathjax option page. This allows an attacker to specify arbitrary javascript that will be loaded with each post and also loaded onto the homepage of the wordpress blog.
Mitigation:
The Vendor Was notified and a patch was released: Patched Version: http://downloads.wordpress.org/plugin/mathjax-latex.1.2.1.zip See ChangeLog: http://wordpress.org/extend/plugins/mathjax-latex/changelog/