4.9
CVSSv2

CVE-2021-24823

Published: 28/02/2022 Updated: 07/03/2022
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

The Support Board WordPress plugin prior to 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow malicious users to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schiocco support board