CVE-2017-20065

MEDIUM

Supsystic Popup Plugin <1.7.6 - CSRF

Title source: llm

Description

A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by Radjnies Bhansingh · htmlwebappsphp
https://www.exploit-db.com/exploits/41485

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
supsystic/popup 1.7.6
Published Jun 20, 2022
Tracked Since Feb 18, 2026