CP Polls是dwbooster个人开发者的一个投票插件工具。 dwbooster CP Polls 1.0.8版本存在跨站请求伪造漏洞,该漏洞源于跨站请求伪造问题,允许攻击者以经过身份验证的用户身份执行未经授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2016-20068 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20069 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20066 | 7.2 HIGH | WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting |
| CVE-2016-20084 | 7.2 HIGH | WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS |
| CVE-2016-20070 | 6.4 MEDIUM | WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS |
No comments yet