What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.
Explanation of Vulnerability in Simple Terms
Clearfy Cache versions up to 2.2.1 contain a cross-site request forgery (CSRF) vulnerability that allows an authenticated attacker to perform unauthorized actions on the site without the site owner's knowledge. The vulnerability requires the attacker to trick a logged-in administrator into visiting a malicious page. An attacker can modify site settings or cache configuration through forged requests.
What an attacker can do
Modify site settings or cache configuration by tricking a logged-in admin into visiting a malicious page.
Potential impact on your site
An attacker can alter your cache settings or site configuration if an admin visits a malicious link while logged in.
Conditions required to exploit
Attacker needs a low-privilege account (e.g., subscriber or contributor) and must trick an admin into visiting a malicious link.
Key dates
External resources
Related vulnerabilities