A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
References
Link | Resource |
---|---|
http://get-simple.info/extend/plugin/my-smtp-contact/1221/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-08-10 16:15
Updated : 2021-08-19 10:03
NVD link : CVE-2021-29400
Mitre link : CVE-2021-29400
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
netexplorer
- my_smtp_contact