CVE-2013-2697
Published Apr 19, 2013
Last updated 12 years ago
Overview
- Description
- Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- Source
- PSIRT-CNA@flexerasoftware.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:lester_chan:wp-downloadmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4FAF020-7F0D-4B05-95F0-C930173A225A", "versionEndIncluding": "1.60" }, { "criteria": "cpe:2.3:a:lester_chan:wp-downloadmanager:1.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A25723E-85F8-49DF-AC82-D93BF442C8AA" }, { "criteria": "cpe:2.3:a:lester_chan:wp-downloadmanager:1.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCB9E593-9DEC-4055-9C57-241D329DE0CD" }, { "criteria": "cpe:2.3:a:lester_chan:wp-downloadmanager:1.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF1422F8-6FE0-4C8E-BAF0-557117F4783B" }, { "criteria": "cpe:2.3:a:lester_chan:wp-downloadmanager:1.40:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78C619A5-3DDB-44BA-AEA4-176AB5D30546" }, { "criteria": "cpe:2.3:a:lester_chan:wp-downloadmanager:1.50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72738FA5-5010-4DA4-BA44-AC901D8F3DFA" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:wordpress:wordpress:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A77EB0E7-7FA7-4232-97DF-7C7587D163F1" } ], "operator": "OR" } ], "operator": "AND" } ]