CVE-2015-20105

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
References
Link Resource
https://seclists.org/bugtraq/2015/May/45 Exploit Mailing List Third Party Advisory
https://wpscan.com/vulnerability/2bc3af7e-5542-40c4-8141-7c49e8df68f0 Exploit Third Party Advisory
https://packetstormsecurity.com/files/131814/ Exploit Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:cbads:clickbank_affiliate_ads:*:*:*:*:*:*:*:*

Information

Published : 2021-12-02 10:15

Updated : 2021-12-03 18:37


NVD link : CVE-2015-20105

Mitre link : CVE-2015-20105


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

cbads

  • clickbank_affiliate_ads