lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <2cb4cb8b-7e1f-f26d-48c4-eb1674f2e073@securify.nl> Date: Tue, 19 Jul 2016 21:56:32 +0200 From: Summer of Pwnage <lists@...urify.nl> To: fulldisclosure@...lists.org Subject: [FD] Cross-Site Request Forgery in Icegram WordPress Plugin ------------------------------------------------------------------------ Cross-Site Request Forgery in Icegram WordPress Plugin ------------------------------------------------------------------------ Yorick Koster, July 2016 ------------------------------------------------------------------------ Abstract ------------------------------------------------------------------------ A Cross-Site Request Forgery vulnerability was found in the Icegram WordPress Plugin. This issue allows an attacker to overwrite any WordPress option with the value true. An attacker may use this issue to enable (vulnerable) WordPress features that are disabled in the target site. ------------------------------------------------------------------------ OVE ID ------------------------------------------------------------------------ OVE-20160712-0032 ------------------------------------------------------------------------ Tested versions ------------------------------------------------------------------------ This issue was successfully tested on the Icegram - Popups, Optins, CTAs & lot more... WordPress Plugin version 1.9.18. ------------------------------------------------------------------------ Fix ------------------------------------------------------------------------ This issue is resolved in Icegram 1.9.19. ------------------------------------------------------------------------ Details ------------------------------------------------------------------------ https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_icegram_wordpress_plugin.html ------------------------------------------------------------------------ Summer of Pwnage (https://sumofpwn.nl) is a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way. _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists