CVE-2023-0763
EUVD-2023-1278015.05.2023, 13:15
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| infigosoftware | clock_in_portal-_staff_\&_attendance_management | 𝑥 ≤ 2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration