CVE-2014-2838
GD Star Rating <= 1.9.22 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct (1) SQL injection attacks via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php or (2) cross-site scripting (XSS) attacks via unspecified vectors.
Múltiples vulnerabilidades de CSRF en el plugin GD Star Rating 19.22 para WordPress permiten a atacantes remotos secuestrar la autenticación de administradores para solicitudes que realizan (1) ataques de inyección SQL a través del parámetro s en la página gd-star-rating-stats en wp-admin/admin.php o (2) ataques de XSS a través de vectores no especificados.
Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 1.9.22 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct (1) SQL injection attacks via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php or (2) cross-site scripting (XSS) attacks via unspecified vectors.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-28 CVE Published
- 2014-04-10 CVE Reserved
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-08-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/57667 | Third Party Advisory | |
https://advisories.dxw.com/advisories/csrf-and-blind-sql-injection-in-gd-star-rating-1-9-22 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/92156 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://seclists.org/fulldisclosure/2014/Mar/399 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dev4press Search vendor "Dev4press" | Gd Star Rating Search vendor "Dev4press" for product "Gd Star Rating" | 19.22 Search vendor "Dev4press" for product "Gd Star Rating" and version "19.22" | wordpress |
Affected
|