Sploitus

CVE-2014-9129

1 known exploit for CVE-2014-9129

Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.

Affected products
Cm Download Manager
Cminds Cm Download Manager
≤ 2.0.6
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
1.5% (73th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2014-12-05
CVE-2014-9129 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-9129

Proof-of-concept code and exploit modules indexed by Sploitus