CVE-2023-0763
15.05.2023, 13:15
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack
Vendor | Product | Version |
---|---|---|
infigosoftware | clock_in_portal-_staff_\&_attendance_management | 𝑥 ≤ 2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration