Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Sunil Nanda Subscribe
Filtered by product Blue Wrench Video Widget
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-6797 1 Sunil Nanda 1 Blue Wrench Video Widget 2013-11-19 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that embed arbitrary URLs via the bw_url parameter in the bw-videos page to wp-admin/admin.php, as demonstrated by embedding a URL to a JavaScript file.