Vulnerabilities and security researches forgsheetconnector-ninja-forms gsheetconnector-ninja-forms
Direction: ascendingJun 07, 2024
Ninja Forms Google Sheet Connector # 48c876c4c37ae47cdbba572acd132e945788cdbd
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- Ninja Forms Google Sheet Connector [gsheetconnector-ninja-forms] < 1.2.2 WordPress Ninja Forms Google Sheet Connector plugin < 1.2.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Ninja Forms Google Sheet Connector plugin (versions < 1.2.2).
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Ninja Forms Google Sheet Connector # CVE-2023-2333
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 04, 2023
- Research Description
- The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected versions
-
Min -, max -.
- Status
-
vulnerable