PT-2025-44959 · Sugiartha+1 · Mapmap
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MapMap versions prior to 1.2
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation—a security mechanism used to ensure that a request was intentionally sent by the user. The issue resides in the
admin shortcode submit(), admin configuration submit(), and admin shortcode delete() functions. This allows unauthenticated attackers to update plugin settings and inject malicious web scripts by tricking a site administrator into clicking a forged link.Recommendations
Update MapMap to version 1.2 or later.
As a temporary workaround, restrict access to the
admin shortcode submit(), admin configuration submit(), and admin shortcode delete() functions.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mapmap