What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in julian.weinert cSlider cslider allows Cross Site Request Forgery.This issue affects cSlider: from n/a through <= 2.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in julian.weinert cSlider cslider allows Cross Site Request Forgery.This issue affects cSlider: from n/a through <= 2.4.2.
Explanation of Vulnerability in Simple Terms
cSlider versions 2.4.2 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a site administrator, performs unwanted actions on the cSlider component without the admin's knowledge or consent. The attack requires the admin to visit the attacker's page while logged into the site. Successful exploitation can lead to unauthorized changes to slider configuration or content.
What an attacker can do
Perform unwanted actions on cSlider (such as modifying slider settings or content) by tricking a logged-in admin into visiting a malicious webpage.
Potential impact on your site
An admin's cSlider configuration or content could be altered without their knowledge if they visit a malicious link while logged in.
Conditions required to exploit
Site administrator must be logged in and visit an attacker-controlled webpage; no special privileges or complex setup required.
Key dates
External resources
Related vulnerabilities