CVE-2024-7864

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-09-13 06:15

Updated : 2024-09-27 21:26


NVD link : CVE-2024-7864

Mitre link : CVE-2024-7864

CVE.ORG link : CVE-2024-7864


JSON object : View

Products Affected

pixeljar

  • favicon_generator
CWE
CWE-352

Cross-Site Request Forgery (CSRF)