First published: Tue Mar 12 2019(Updated: )
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Rednao Smart Forms | <=2.6.15 | |
<=2.6.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5924 is a Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier, which allows remote attackers to hijack the authentication of administrators via a specially crafted page.
CVE-2019-5924 has a severity level of 8.8 (high).
The vulnerability affects Smart Forms versions up to and including 2.6.15.
To fix CVE-2019-5924, update Smart Forms to a version higher than 2.6.15.
You can find more information about CVE-2019-5924 at the following references: [http://jvn.jp/jp/JVN97656108/index.html](http://jvn.jp/jp/JVN97656108/index.html), [https://wordpress.org/plugins/smart-forms/#developers](https://wordpress.org/plugins/smart-forms/#developers), [https://wpvulndb.com/vulnerabilities/9232](https://wpvulndb.com/vulnerabilities/9232).