CVE-2024-7817
12.09.2024, 06:15
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack
Vendor | Product | Version |
---|---|---|
misiek_photo_album | misiek_photo_album | 𝑥 ≤ 1.4.3 |
michalaugustyniak | misiek_photo_album | 𝑥 ≤ 1.4.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration