cleantalk
Vulnerabilities and Security Researches

Crowdsignal Dashboard – Polls, Surveys & more, d796221c8f4ff160c1fde983ff9c0da466a3c3f3

Published on
Nov 06, 2013
Research Description
Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.21 Crowdsignal Dashboard < 2.0.21 - Cross-Site Request Forgery The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.0.21. This is due to missing or incorrect nonce validation in the rating_settings function. This makes it possible for unauthenticated attackers to have an unknown impact via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.0.21.
Status
vulnerable