PT-2024-37322 · WordPress · Music Request Manager

Bob Matyas

·

Published

2024-09-11

·

Updated

2024-09-13

·

CVE-2024-6019

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Music Request Manager WordPress plugin versions 1.3 and earlier
Description: The issue allows unauthenticated users to perform Cross-Site Scripting attacks against administrators due to the plugin's failure to sanitise and escape incoming music requests. This could potentially lead to malicious actions being executed on the administrator's account.
Recommendations: For Music Request Manager WordPress plugin versions 1.3 and earlier, update to a version that properly sanitises and escapes incoming music requests to prevent Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6019

Affected Products

Music Request Manager