What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.
Explanation of Vulnerability in Simple Terms
JS & CSS Script Optimizer versions up to 0.3.3 lack CSRF protection on administrative actions. An attacker can craft a malicious webpage that, when visited by a logged-in site admin, performs unwanted changes to the plugin's settings without the admin's knowledge or consent. The attacker cannot read sensitive data, only modify plugin configuration.
What an attacker can do
Trick a logged-in admin into visiting a malicious page that changes the plugin's settings without their consent.
Potential impact on your site
Plugin settings can be altered by attackers without admin action, potentially breaking site optimization or exposing unintended configuration.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled webpage; no special privileges or direct site access required.
Key dates
External resources
Related vulnerabilities