cleantalk
Vulnerabilities and Security Researches

Crony Cronjob Manager, CVE-2017-14530

CVE, Research URL

CVE-2017-14530

Application

Crony Cronjob Manager

Published on
Sep 18, 2017
Research Description
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
Affected versions
max 0.4.7.
Status
vulnerable