CVE-2021-24913

CVE-2021-24913: Logo Showcase with Slick Slider < 2.0.1 - Arbitrary Media Title/Description/Alt Text/URL Update via CSRF

Vendor Unknown
Product Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid
Weakness CWE-352 · CSRF
Published February 28, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in high privilege user, change title, description, alt text, and URL of arbitrary uploaded media.

Key dates

02Disclosure timeline

February 28, 2022 CVE published
August 3, 2024 Record updated