What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in dalziel Windows Live Writer windows-live-writer allows Stored XSS.This issue affects Windows Live Writer: from n/a through <= 0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in dalziel Windows Live Writer windows-live-writer allows Stored XSS.This issue affects Windows Live Writer: from n/a through <= 0.1.
Explanation of Vulnerability in Simple Terms
Windows Live Writer versions 0.1 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in user, performs unwanted actions within the application without the user's knowledge. The attack requires the victim to visit the attacker's page while authenticated. Impact includes unauthorized data modification and limited information disclosure.
What an attacker can do
Perform unwanted actions (read, modify, or delete data) on behalf of a logged-in user without their consent.
Potential impact on your site
Users' accounts and data can be compromised if they visit malicious sites while using the application.
Conditions required to exploit
Victim must be logged into Windows Live Writer and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities