PT-2025-44953 · Lmbbox+1 · Lmb^Box Smileys
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LMB^Box Smileys versions prior to 3.3
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
manage page() function. This allows unauthenticated attackers to update settings and inject malicious web scripts by tricking a site administrator into clicking a forged link. Nonce validation is a security measure used to ensure that a request was intentionally sent by the user and not forged by a third party.Recommendations
Update the plugin to a version newer than 3.2.
As a temporary workaround, restrict access to the
manage page() function to minimize the risk of exploitation.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lmb^Box Smileys