What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <= 3.5.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <= 3.5.5.
Explanation of Vulnerability in Simple Terms
Grand Magazine versions up to 3.5.5 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unwanted actions on behalf of site visitors. An attacker can craft a malicious link or page that, when visited by a logged-in admin or user, triggers unintended changes or deletions. The vulnerability requires user interaction and does not expose sensitive data directly, but can compromise site integrity.
What an attacker can do
Trick a logged-in user into performing unwanted actions like changing settings or deleting content.
Potential impact on your site
Site admins or users could unknowingly modify or delete content, change settings, or perform other actions without their consent.
Conditions required to exploit
Victim must visit attacker's malicious link or page while logged into the site.
Key dates
External resources
Related vulnerabilities