videousermanuals White Lable CMS (white-label-cms) plugin for Wordpress 1.5

CPE Details

videousermanuals White Lable CMS (white-label-cms) plugin for Wordpress 1.5
1.5
2012-10-24
16h26 +00:00
2012-10-26
16h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:videousermanuals:white-label-cms:1.5:*:*:*:*:*:*:*

Informations

Vendor

videousermanuals

Product

white-label-cms

Version

1.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2012-5387 2012-10-24 08h00 +00:00 Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, as demonstrated by a developer name containing XSS sequences.
6.8
CVE-2012-5388 2012-10-24 08h00 +00:00 Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, a related issue to CVE-2012-5387.
3.5