CVE-2023-0762
15.05.2023, 13:15
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attackEnginsight
Vendor | Product | Version |
---|---|---|
infigosoftware | clock_in_portal-_staff_\&_attendance_management | 𝑥 ≤ 2.1 |
𝑥
= Vulnerable software versions