Unrated severityNVD Advisory· Published Jun 27, 2022· Updated Aug 3, 2024
Cimy Header Image Rotator <= 6.1.1 - Arbitrary Settings Update via CSRF
CVE-2022-1885
Description
The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected products
1- Range: <=6.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/8416cbcf-086d-42ff-b2a4-f3954c8ff0c8mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.