What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue affects Maintenance Notice: from n/a through <= 1.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue affects Maintenance Notice: from n/a through <= 1.0.6.
Explanation of Vulnerability in Simple Terms
The Maintenance Notice plugin for CodeVibrant contains a cross-site request forgery (CSRF) vulnerability in versions 1.0.6 and earlier. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, performs unwanted actions on the site without the administrator's knowledge or consent. The vulnerability requires user interaction and affects only the integrity of site data, not confidentiality or availability.
What an attacker can do
Trick a site admin into visiting a malicious page that performs unwanted actions on the site.
Potential impact on your site
Administrators could unknowingly trigger unintended changes to site settings or data via CSRF attacks.
Conditions required to exploit
Admin must visit attacker-controlled page while logged into the site.
Key dates
External resources
Related vulnerabilities