6.8
CVSSv2

CVE-2013-6797

Published: 19/11/2013 Updated: 19/11/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin prior to 2.0.0 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that embed arbitrary URLs via the bw_url parameter in the bw-videos page to wp-admin/admin.php, as demonstrated by embedding a URL to a JavaScript file.

Vulnerable Product Search on Vulmon Subscribe to Product

sunil nanda blue wrench video widget 1.0.0

sunil nanda blue wrench video widget 1.0.4

sunil nanda blue wrench video widget 1.0.2

sunil nanda blue wrench video widget

sunil nanda blue wrench video widget 1.0.3

sunil nanda blue wrench video widget 1.0.1

Exploits

source: wwwsecurityfocuscom/bid/63800/info The Blue Wrench Video Widget plugin for WordPress is prone to a cross-site request-forgery vulnerability An attacker can exploit the cross-site request forgery issue to perform unauthorized actions in the context of a logged-in user of the affected application This may aid in other attacks B ...