6.8
CVSSv2

CVE-2014-9398

Published: 31/12/2014 Updated: 03/01/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and previous versions for WordPress allows remote malicious users to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the mashtlb_twitter_username parameter in the twitter-liveblog.php page to wp-admin/options-general.php.

Vulnerable Product Search on Vulmon Subscribe to Product

twitter liveblog project twitter liveblog

Exploits

WordPress Twitter LiveBlog plugin version 112 suffers from cross site request forgery and cross site scripting vulnerabilities ...