Title: CSRF leads to account takeover Wordpress plugin Gtranslate
CVE ID: CVE-2022-0770
CVSSv3 Base Score: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Vendor: Translate AI Multilingual Solutions
Products: Wordpress Plugin Gtranslate
Advisory Release Date: 22-07-2022
Advisory URL: https://labs.integrity.pt/advisories/cve-2022-0770
Credits: Discovery by Diogo Real <dr[at]integrity.pt>
Due to a vulnerability of Cross-Site Request Forgery and a debug feature, it is possible for an attacker to create a malicious URL that if visited by the victim will write their authentication cookies to a file publicly available for an attacker leading to account takeover.
© 2024 INTEGRITY S.A. All rights reserved. | Cookie Policy