What the vulnerability does
01Description
Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.
Explanation of Vulnerability in Simple Terms
Uncanny Automator Pro versions up to 5.3 contain a vulnerability that allows an attacker to modify site content or cause temporary unavailability. The attack requires a victim to click a malicious link or visit a compromised page. No authentication is needed, but user interaction is required to trigger the vulnerability.
What an attacker can do
Modify site content or cause temporary service disruption via a malicious link.
Potential impact on your site
Site content could be altered or the site could become temporarily unavailable without warning.
Conditions required to exploit
Victim must click a link or visit a page controlled by the attacker.
Key dates
External resources