6.8
CVSSv2

CVE-2014-9129

Published: 05/12/2014 Updated: 02/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin prior to 2.0.7 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cminds cm download manager

Exploits

WordPress CM Download Manager plugin versions 206 and below suffer from cross site request forgery and cross site scripting vulnerabilities ...