CVE-2021-29400

MEDIUM

My SMTP Contact 1.1.1 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://get-simple.info/extend/plugin/my-smtp-contact/1221/

Scores

CVSS v3 6.5
EPSS 0.0056
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-352
Status published
Products (1)
netexplorer/my_smtp_contact 1.1.1
Published Aug 10, 2021
Tracked Since Feb 18, 2026