What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in ryscript NV Slider nv-slider allows Stored XSS.This issue affects NV Slider: from n/a through <= 1.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in ryscript NV Slider nv-slider allows Stored XSS.This issue affects NV Slider: from n/a through <= 1.6.
Explanation of Vulnerability in Simple Terms
NV Slider versions 1.6 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the slider without their knowledge. The attack requires the victim to visit the attacker's page while authenticated to the site. This can lead to unauthorized changes to slider configuration or content.
What an attacker can do
Perform unwanted actions on the slider (modify settings, content) by tricking an authenticated admin into visiting a malicious page.
Potential impact on your site
An attacker can modify slider settings or content without authorization if an admin visits a malicious link while logged in.
Conditions required to exploit
Victim must be logged in to the site and visit an attacker-controlled webpage while authenticated.
Key dates
External resources
Related vulnerabilities