What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1.4.
Explanation of Vulnerability in Simple Terms
Modal Window versions 6.1.4 and earlier contain a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in user, performs unwanted actions on the user's behalf. The vulnerability requires user interaction—the victim must visit the attacker's page—but does not require authentication to the Modal Window component itself.
What an attacker can do
Perform unwanted actions on behalf of a logged-in user without their knowledge or consent.
Potential impact on your site
Users' accounts can be compromised to perform unintended actions; site integrity and user trust may be affected.
Conditions required to exploit
Victim must visit an attacker-controlled webpage while logged into a site using Modal Window.
Key dates
External resources
Related vulnerabilities