CVE-2014-9129
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.
- Affected products
- Cm Download Manager
- Cminds Cm Download Manager
- ≤ 2.0.6
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 1.5% (73th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2014-12-05
CVE-2014-9129 at NVD
1 known exploit for CVE-2014-9129
Proof-of-concept code and exploit modules indexed by Sploitus