Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page.
References
Link | Resource |
---|---|
https://www.xml-sitemaps.com/news-20210831.html | Release Notes Vendor Advisory |
https://jvn.jp/en/jp/JVN58407606/index.html | Third Party Advisory |
https://www.xml-sitemaps.com/standalone-google-sitemap-generator.html | Product Vendor Advisory |
Configurations
Information
Published : 2021-11-24 08:15
Updated : 2021-11-26 20:02
NVD link : CVE-2021-20845
Mitre link : CVE-2021-20845
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
xml-sitemaps
- unlimited_sitemap_generator