PT-2022-15296 · Unknown · Image Slider

Marco Wotschka

·

Published

2022-07-18

·

Updated

2023-10-24

·

CVE-2022-2223

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Image Slider versions up to, and including 1.1.121
Description The issue arises from a failure to properly check for the existence of a nonce in the ewic duplicate slider function, making it possible for unauthenticated attackers to duplicate existing posts or pages if they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For versions up to, and including 1.1.121, consider disabling the ewic duplicate slider function until a patch is available to prevent exploitation. Restrict access to administrative actions to minimize the risk of attackers tricking site administrators into performing unintended actions.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2223

Affected Products

Image Slider