mirror of
https://github.com/0xMarcio/cve.git
synced 2026-04-21 09:56:14 +02:00
761 B
761 B
CVE-2017-14530
Description
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
POC
Reference
- https://cybersecurityworks.com/zerodays/cve-2017-14530-crony.html
- https://github.com/cybersecurityworks/Disclosed/issues/9