cleantalk
Vulnerabilities and Security Researches

SlimStat Analytics, 4fbce60766f41ab69ebf656812aed786c85670f7

Application

SlimStat Analytics

Published on
May 22, 2019
Research Description
SlimStat Analytics [wp-slimstat] < 4.8.4 Slimstat Analytics <= 4.8.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting The Slimstat Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.3. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 4.8.4.
Status
vulnerable